SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Okta launches Agent SSO to manage enterprise AI agent access

Okta launches Agent SSO to manage enterprise AI agent access

Wed, 26th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Okta has launched Agent SSO for AI agents, which is now generally available to customers.

The launch brings the Cross App Access protocol into Okta's identity platform and aims to give companies a way to manage AI agents through the same identity controls used for staff. The approach is intended to reduce reliance on static API keys, unmanaged links between tools, and repeated user consent requests.

Many businesses are grappling with how to govern software agents that connect to enterprise applications and act on behalf of workers. Okta says many organisations have adopted AI agents across workflows, but far fewer apply the same identity and security rules to those agents as they do to employees.

Agent SSO allows an AI agent that uses Cross App Access, or XAA, to be registered as an identity in Okta's Universal Directory. That lets security teams assign and update access policies for agents in the same administrative environment used for human identities.

Okta says this shifts authorisation decisions from individual applications to the identity provider layer. In practice, it gives administrators a central point to decide which applications, APIs, tools, and Model Context Protocol servers an agent can access.

Managing visibility

The release comes as companies try to address a broader governance problem around workplace AI. Okta cited research showing only 34% of organisations apply the same identity and security controls to AI agents as they do to human employees.

In Asia Pacific, the company pointed to a gap between adoption and management: 91% of organisations in the region are already using AI agents, while only 10% have a well-developed strategy for managing them.

"Across Asia Pacific, organisations are moving quickly to put AI agents to work, but many are still figuring out how to manage them. Okta research shows 91% of organisations are already using AI agents, yet only 10% have a well-developed strategy for managing them. As agents connect to more enterprise applications and act on behalf of employees, organisations need to know where they are, what they can access, and who they're acting on behalf of. Agent SSO gives security teams a way to manage that access through the identity policies and controls they already have in place, rather than having to build a separate security model for AI," said Stephanie Barnett, Vice President, Presales, Asia Pacific & Japan, Okta.

In Australia, Okta highlighted a different mismatch between executive confidence and worker behaviour. It said 94% of Australian executives believed they had visibility into AI use, while nearly 60% of workers said they were using unapproved AI tools.

"In Australia, there's a significant gap between how much visibility leaders think they have over AI and what's actually happening across their workforce. Our latest research found 94% of Australian executives were confident they had visibility into AI use, yet nearly 60% of workers said they were using unapproved AI tools. As AI agents increasingly connect to applications and act on behalf of employees, that visibility gap becomes even more important. Organisations need to know which agents are operating across their environment and what they can access. Agent SSO gives security teams a way to manage that access through the identity policies and controls they already have in place," said Barnett.

Industry standard

According to Okta, XAA is an open protocol built as an extension of OAuth and incorporated as the Enterprise-Managed Authorization extension for Model Context Protocol. The standard is designed to let identity controls follow agents across applications rather than leaving each connection to be handled separately.

Okta has presented Agent SSO as a core layer in what it calls a blueprint for governing AI agents. That framework centres on three questions for companies: where their agents are, what those agents can connect to, and what they are authorised to do.

As described by Okta, Agent SSO addresses the first two by registering supported agents in its directory and using short-lived tokens in place of hardcoded credentials or broad authorisations. Wider oversight of agent behaviour during operation would sit under a separate product, Okta for AI Agents.

Cross App Access integrations are also available through the Okta Integration Network, which supports a range of AI agents, software applications, and platforms. Named examples include Anthropic's Claude, Asana, Atlassian, Canva, Datadog, Figma, Notion, Slack, and Supabase.

Ric Smith, President of Products and Technology at Okta, said the company sees the shift to AI agents as comparable to an earlier move to centralised login for staff access. "Okta is an undisputed leader in SSO, and now we're bringing SSO for your AI agents. AI agents are fast becoming a primary interface for how work gets done, but granting them access to enterprise systems shouldn't require trading away security or visibility. With Agent SSO, we are helping to establish a fundamental security standard for the agentic enterprise. By treating every connected agent as a first-class identity and bundling this capability directly into our core SSO offering, Okta is making it effortless for enterprises to secure AI workflows from day one," said Smith.