AsiaTechDaily – Asia's Leading Tech and Startup Media Platform
Okta has announced the general availability of Agent SSO, a new capability that brings the company’s Cross App Access (XAA) standard into its core Single Sign-On product and allows enterprises to manage AI agents as first-class identities alongside human employees. The capability is now available to Okta’s more than 20,000 customers.
Agent SSO is designed to address part of that gap by giving security teams centralized visibility and control over supported AI agents. Instead of relying on static API keys, fragmented connections or repeated user consent, organizations can register agents in Okta’s Universal Directory and manage their access through centralized policies.
The development builds on Cross App Access, an open standard introduced by Okta in 2025 to manage how applications and AI agents access other applications. XAA extends OAuth and allows enterprises to move authorization decisions away from individual applications and into the identity provider. Under Agent SSO, an XAA-supported AI agent can be registered as a workload principal and connected to an XAA-enabled application through Okta. Administrators can manage these connections through the Okta Admin Console rather than requiring users to repeatedly approve individual access requests.
The system also uses identity-governed, short-lived tokens instead of relying on hardcoded credentials. This is intended to give security teams greater control over which applications, APIs, tools and Model Context Protocol (MCP) servers an agent can access. For example, an organization using Anthropic’s Claude can register the agent within Okta and apply enterprise access policies to its connections, allowing administrators to manage the agent alongside other identities.
“Okta is an undisputed leader in SSO, and now we’re bringing SSO for your AI agents,” said Ric Smith, President of Products and Technology at Okta. “AI agents are fast becoming a primary interface for how work gets done, but granting them access to enterprise systems shouldn’t require trading away security or visibility. With Agent SSO, we are helping to establish a fundamental security standard for the agentic enterprise. By treating every connected agent as a first-class identity and bundling this capability directly into our core SSO offering, Okta is making it effortless for enterprises to secure AI workflows from day one.”
The need for dedicated agent identities reflects a broader change in enterprise computing. Traditional identity systems were largely designed around employees, customers, applications and relatively stable workloads. AI agents can behave differently. They can be created dynamically, interact with multiple systems and execute actions autonomously, making ownership, permissions and lifecycle management more difficult.
Microsoft has taken a similar approach with Microsoft Entra Agent ID, which provides dedicated identities for AI agents and extends access management, lifecycle governance, Conditional Access and monitoring to those identities. Microsoft describes agent identities as a way to distinguish actions performed by AI agents from those performed by employees, customers or conventional workloads. This indicates that agent identity is becoming a distinct enterprise infrastructure category rather than simply an extension of existing application authentication.
The identity problem is also becoming more complicated as agents connect to increasingly diverse ecosystems. AI agents can use MCP to access external tools and resources, while agent-to-agent systems allow autonomous software to communicate with other agents. As these connections multiply, enterprises need to determine not only which agents exist, but also which systems they can access and under whose authority they are operating.
Okta’s broader framework divides the governance problem into three questions: Where are my agents? What can they connect to? What can they do? Agent SSO primarily addresses the first two. It creates a centralized identity for supported agents and governs their connections to sanctioned applications and resources. Okta’s separate Okta for AI Agents offering is designed to extend governance further by discovering unmanaged agents, managing their lifecycle and applying runtime controls.
That distinction is important because giving an agent an identity does not automatically make its actions safe. An authorized agent can still misuse legitimate access, making monitoring, least-privilege policies and runtime controls increasingly important.
Okta’s launch comes as major technology companies build infrastructure specifically for AI-agent identity and authorization. Microsoft’s Entra Agent ID is now generally available and provides identity constructs, lifecycle management and access governance for agents. Okta, meanwhile, is embedding agent identity directly into its existing workforce SSO infrastructure.
The direction suggests that enterprises are beginning to treat autonomous software as a new category of organizational actor. That shift could become increasingly important as companies move from AI assistants that respond to user prompts toward agents that independently retrieve information, call APIs, update systems and execute workflows. For identity providers, the challenge is consequently expanding beyond authenticating people. They must also establish reliable answers to questions around agent ownership, authorization, lifecycle, accountability and auditability.
Okta’s Agent SSO launch represents one step in that transition. By bringing AI agents into an existing enterprise identity layer, the company is betting that autonomous software will need many of the same foundational controls that have governed human access for years, but with tighter permissions, shorter-lived credentials and significantly greater emphasis on continuous oversight. As enterprises scale their agentic workforce, the identity attached to an AI agent may become just as important as the model powering it.