Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Palo Alto Networks: Securing Machine Identities and AI Agents at Scale

Palo Alto Networks
08/04/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


They don't just execute the predefined instructions. They make decisions. They don't just interact with system during office hours. They work all the time, continuously. They act like humans, but at the scale and the speed of the machine. When we look at machine identities, we're dealing with an entirely different scale. Look at the swarm on the screen. The ratio is already 109 machines to a single human. It's going to be 110 soon. And with the fast adoption of AI agents, it's growing faster than ever before. Think about what makes up your infrastructure today. Every automated process, every microservice, every container, every AI agent, these are all identities. They all need to be authenticated. Many of them need privileges and secrets to do their job. And every single one of them introduces risk. The wave that you see on the screen represents sprawl. Not just a sprawl of secrets, also a sprawl of unknown machine identities and scattered vaults. And together, they create a massive hidden security blind spot. And the sheer number of these machines is exploding. They spin up. They do their job. And they disappear. And because of that, the security solutions around them must evolve. Because when you have unknown identities and scattered vaults, you lack centralized governance. And you lack control. If you see just a sea of alerts without any context, where do you start? How do you prioritize? The manual processes can't simply keep up with the modern technology and scale. To secure a dynamic environment, automation is an absolute must. Because if our solutions do not evolve, we don't just lose visibility. We lose control. All right, so we introduced the risk. Now let's understand how we solve them. Previously, we introduced Secrets Hub to give you centralized visibility and control over your external vaults. But the environment is moving faster than ever. So today, we're adding the automation at scale that machine identity security truly needs. Whether your secrets are in AWS, Azure, GCP, HashiCorp, we find them. We remove the friction. No more complex setups. No more manual configurations. You can just onboard them to our platform with a single click and start managing it centrally. But here's the most important part. We've added all that power without changing the developer workflow. Your developers can stay on the environments they love. They keep their velocities. But you, all of you, you get centralized control that you've been looking for. We didn't just update Secrets Hub. We made it work at the scale and the speed of the machine. Now let's take a deeper look. We're also adding a brand new era of frisk and centralized visibility for machines. Managed secrets, unmanaged secrets, external vaults, even our own SaaS. Everything is now unified in a single automated view. But we don't stop there. We're going deeper. We're going into the ephemeral world. Those identities that live just for a second, we see them. All those pesky, janky CICD pipelines that used to be blind spots, we inventory them for you. We discover credentials and workloads automatically. We're taking the unknown out of your environment and replacing it with absolute clarity. Lastly, giving machines a strong way to fetch secrets has been our focus for years. But we want to take it a step forward. Because I showed you a sprawl. But how can you regain control over your sprawl without having a true zero trust solution for machines? Up until now, most of the industry secured this application based on what they know, a secret or a credential. But here's the problem. If an attacker steals a secret, he is instantly trusted. This is a fundamental identity problem. We have to shift the focus to who the app is. So what's our solution? Today, we're introducing secure workload access, which solves this by issuing universal SPIFI-based identities. It doesn't matter if it's a Kubernetes pod, a VM, or an AI agent. Before they can do anything, they have to improve their DNA through continuous attestation. But here's the real breakthrough in all this. Those identities that we're issuing, they're ephemeral. They live for minutes, even seconds. And in case the identity is compromised by an attacker somehow, it is already gone. We are dramatically reducing the risk of forever secrets. This is the ultimate shift left. We manage the machine identity from day one. We're not just securing your workloads. We're giving them proven identity that finally makes zero trust for machines a reality. Now, we talked a lot. Let's see it in action and walk through how we are protecting machine identities. The Command Center provides us a high-level view of an organization's machine identity posture. The Machine Identity Inventory gives us the discovered machine identities, both managed and unmanaged. Let's look at the machine identities that are of high risk and those that need to be onboarded. We will look at the Jenkins pipeline. The details provide all the metadata. From the Privileges tab, we see that the machine identity has access to a lot of secrets. And we have identified two risks. Let us address the first risk by automatically onboarding the machine identity to the Adira platform. The modern SPIFFI Authenticator provides us the most secure way to authenticate. In addition, we will also create the voltage secrets to use SPIFFI SVID with a simple toggle. The summary screen shows that the ML training pipeline will be configured to use SPIFFI where applicable. Create and Promote will onboard this machine identity and will be confirmed by the newly listed Authenticator. SPIFFI-based authentication is now enforced, significantly hardening the machine identity posture as reflected in the Command Center. By replacing those static secrets with the SPIFFI-based identities, we've moved from what we saw previously, the unmanned secret sprawl, to a clear and verifiable machine identity posture. Look, we talked about, and we will talk more about the massive scale of AI agents. And we talked about the power of SPIFFI just now. But the reality check, we know the reality of your infrastructure. Your infrastructure is not just one thing. It is multi-cloud. It is hybrid. It is multi-generational. You have legacy applications that still run your business right now. Most security companies will tell you, just leave them behind or modernize them. We don't. We believe that even legacy apps deserve modern machine identity. And we're doing so by providing a model that is truly any to any to any. Any workload, from the oldest mainframe to the newest AI agent, can use any access method, a secret, a token, a certificate, it doesn't matter, and connect to any target, on cloud, on-prem, the works. We're bridging the gap between the debt of the past and the requirements of the AI era. With Idera's machine identity security, you don't have to choose between modernization and security. We give you both. All right, unit's coming. Let's talk about the new class of identity. AI agents, we talked about them. Peretz, Nikesh talked about them. They're not just another workload in your stack, right? They don't just execute the predefined instructions. They make decisions. They don't just interact with system during office hours. They work all the time, continuously. They act like humans, but at the scale and the speed of the machine. And you know, just saying agent is actually generalizing a very complex problem. I want you to keep in mind two distinct agent types that we're going to talk about. Stay alert. There's going to be a pop quiz at the end. First one, Nikesh already mentioned, delegated agents, borrowing the human permissions to perform tasks for us at the speed of light. There are also autonomous agents that trigger workflows and interact with sensitive data with zero human oversight. Both are incredibly advanced, and both are the new frontline of enterprise risk. If you look at the reality of what's going on right now, most organizations have very little visibility into what their agents are doing. They don't know what those agents can access. They cannot distinguish between what is an employee deliberate action, and what is actually an agent that did it on their behalf. Your teams right now are building agents so they can move faster. But by doing so, they are sharing their own identities with those agents. And it doesn't just stop at delegation. Later, those agents will do a great job. They will become autonomous. They will be given secrets, or API keys, or credentials. And they will actively seek more secrets and privileges to do their job. What you are looking at is a potentially huge, huge, huge shadow agentic workforce, completely unsecured, unmonitored, unchecked, and acting with highly privileged permissions. Securing your agentic workforce is not, sorry, is about identity. Every action an agent takes, it takes true in identity. And the only way you can really, really secure agents is to treat them as you would every other employee in your organization. Now, let's hear from Jason on how Carnival are doing just that. Identity is the perimeter. And it is a control plane to where, if you master it, you reduce your chance of breach drastically. To date, I've approved roughly 250 AI use cases. We've pulled back over 2,000 AI agents between Copilot and Bedrock. I knew there was going to be shadow IT. I knew it without a doubt. The fact that it was that bad, though, was an eye opener. You see all sorts of threats around coding AI agents deleting production databases and backups. They did it for one simple reason. They had the permission to destroy something. And that's what we're trying to stop. The partnership would allow me, as a design partner, to have significant input into something brand new, something that might end up being in use all over the world. Using existing cyber technologies to enhance AI around you. Privileged session management, these privileged areas getting access. Palo Alto Networks and Idera's future in what they have planned together is going to be very exciting. A really, really great example of how AI agents can actually be over-provisioned and then just fly under the radar. Thanks, Jason. All right. We talked about the risk of agents with unmonitored privilege. Now let's start talking about some solutions. Earlier this year, we launched AI Agent Identity Security, a comprehensive identity solution for AI agents that's pooling the capabilities that we spent years developing on the Idera platform. And today, we're really happy to share the next stage in how we're securing those AI agent identities. It all starts with the basics. We talked about it. Just assign the AI agent with a modern workload identity, just the one that we announced a few minutes ago. You simply can't govern an agent that you cannot identify throughout its lifecycle. It's as simple as that. But we go further. We're applying fine-grained policies, zero-standing privileges, just-in-time capabilities to ensure that no agent holds the permanent keys to your kingdom. We'll also be integrating secret management capabilities to kill those hard-coded secrets and the much-needed governance and lifecycle capabilities. We're giving your agents the right level of privilege control by leveraging the platform that we've built for over a decade. At RSA conference a few months ago, we changed the game again. We announced that our AI agent identity security solution will be natively integrated into Prisma AIRS 3.0. Think about the force of this integration. AIRS 3.0 solves the visibility gap. It finds and assesses every agent in your ecosystem and allows you to protect it in real time. And with the identity agent model, you can finally assign real identities to all these discover entitlements. You define ownership. You set fine-grained policies. You enforce least-privileged access. But we realized something was missing, a true control plane for AI agents. And we have addressed just that. A couple of weeks ago, we've entered into a definitive agreement to acquire Portkey.AI, a pioneer in AI gateways. With Portkey as our gateway, it will allow us to centrally manage LLMs, MCP, A2A communication, gain deep observability into the agent operation, and really, really make your workforce scale at the enterprise grade that you need. Through AIRS 3.0, you govern every aspect of agent security, not just identity, the full cycle, total control. OK, now let's move one step forward and really understand how we're doing it. Let's start with delegated agents. Look, when an agent asks for a user today, it assumes its identity. It's as simple as that. You lose traceability. You lose accountability. We are restoring that. We provide full audit separation so you can see exactly what the user did and what the agent did on its behalf. But we're not just watching. We'll also be controlling. We enable fine-grained policy down to the MCP level. You define what actions are allowed per user, per agent, and per target. And finally, we're killing the risk of session hijacking. All that authentication that's going on. We're replacing those risky, long-lived access token with short-lived credentials that can talk only to IDRA. No more sharing identities. No more coarse blanket policies. No more anonymous agent actions. Now remember, I mentioned two types of agents earlier. The second type, autonomous agents, are even more dangerous if that's possible. They have fully privileged machine. They have the access. They have the speed. And they have the keys to your house, your secrets, and your credentials. With IDRA, as I said, we solve this by leveraging our unique workload identity. We perform deep attestation of the agent identity. Even if the agent wakes up, performs something at the speed of light, and disappears. But we don't just stop at that. We leverage our secrets management to secure the access path itself. The agent can get the privilege it needs to get the job done, but it never actually sees the secrets. It never touches the keys. We're giving the machine the authority to act, but we're keeping the power in your hands. Now let's look on how IDRA provides the visibility control necessary to secure both delegated and autonomous agents. You can't secure what you can't see. The command center is the place to start. The AI agent inventory page gives you full visibility, building identity into the agent's DNA with unique identity, strong auth, and lifecycle controls. It's security by design, not an afterthought. Let's use Cora to list all the inactive co-pilot agents so relevant actions can be taken. We all use MCP servers. Let's look at the MCP server inventory and check what controls are in place for the AWS MCP server. Cora is recommending some actions. Let's apply them. Security shouldn't be a bottleneck. We empower builders with global guardrails to proactively block catastrophic actions, like dropping a production database or terminating an instance. Ensuring innovation never comes at the cost of data loss. For agents acting on behalf of humans, we apply identity-aware policies. An agent should never be more powerful than the user. By connecting to IDIRA, agents inherit a safe subset of permissions, allowing safe actions while blocking risky ones like repository deletion. Autonomous agents carry the highest risk. Let's ask Cora to list them and focus on one of the agents. Using SPIFFI-based identities for secret list auth, we ensure every action is verifiable. Again, let's apply the recommendations from Cora. For sensitive tasks, the policy triggers a human-in-the-loop flow, granting just-in-time credentials only after explicit approval. Finally, for every action, human or autonomous is captured in a full traceability log. You see who acted, which tool was used, and who authorized it. This is AI Speed with Enterprise Governance. All right, that was a really, really great example of how we took that huge black hole of hygienic risk and actually put it into a fully transparent, governed workshop solution. OK, the future is here now. Everything that I shared is really what it takes to truly secure an hygienic workspace. Because reality is simple. AI agents are no longer a future concern. They're already a part of your environment. They're already interacting with your secret. They're already making decisions. And they're already introducing risk. So the question is really not whether you need to secure them. The only question is whether you're going to be ready.

TL;DR

  • Machine identities now outnumber humans 109:1 and are growing faster with AI agents, creating massive security blind spots through secret sprawl and unknown identities that manual processes cannot manage at scale.
  • Palo Alto Networks' enhanced platform provides one-click vault onboarding, centralized visibility across all secret types, and SPIFFE-based ephemeral identities that live for seconds instead of forever, enabling true zero trust for machines.
  • AI Agent Identity Security distinguishes between delegated and autonomous agents, providing audit separation, fine-grained MCP-level policies, and workload identities with continuous attestation integrated into Prisma AIRS 3.0.
  • The Portkey.AI acquisition delivers a control plane for managing LLMs and agent communication at enterprise scale, while just-in-time credentials and human-in-the-loop flows ensure agents never hold permanent privileged access.
  • The platform bridges legacy and modern infrastructure with an 'any to any to any' model, allowing any workload to use any access method to connect to any target without forcing modernization.

The Machine Identity Crisis

This presentation addresses the explosive growth of machine identities in modern infrastructure, with the ratio already reaching 109 machines to every human and accelerating with AI agent adoption. Every automated process, microservice, container, and AI agent represents an identity requiring authentication and privileges, creating massive security blind spots through secret sprawl, unknown identities, and scattered vaults. The scale and ephemeral nature of these identities — spinning up, executing tasks, and disappearing — means traditional manual security processes cannot keep pace, making automation essential for maintaining visibility and control.

Unified Machine Identity Security Platform

Palo Alto Networks introduces enhanced capabilities for their machine identity security platform, including one-click onboarding for external vaults across AWS, Azure, GCP, and HashiCorp through Secrets Hub. The platform provides centralized visibility across managed secrets, unmanaged secrets, external vaults, and ephemeral identities including CI/CD pipelines. A key innovation is Secure Workload Access, which issues universal SPIFFE-based identities that require continuous attestation before workloads can access resources. These ephemeral identities live for minutes or seconds, dramatically reducing the risk of credential theft compared to static secrets.

AI Agent Identity and Governance

The session introduces comprehensive AI Agent Identity Security capabilities, distinguishing between delegated agents (borrowing human permissions) and autonomous agents (operating with zero human oversight). The solution integrates with Prisma AIRS 3.0 to discover and assess every agent in the ecosystem, while the acquisition of Portkey.AI provides a control plane for centrally managing LLMs, MCP servers, and agent-to-agent communication. For delegated agents, the platform provides full audit separation between user and agent actions, fine-grained policies down to the MCP level, and short-lived credentials to prevent session hijacking. Autonomous agents receive SPIFFE-based workload identities with deep attestation and secrets management that allows privilege access without exposing credentials.

Chapters

0:00 - Machine Identity Scale Challenge
2:04 - Secrets Hub Automation
4:00 - Secure Workload Access Introduction
5:37 - Platform Demo: SPIFFE Onboarding
8:23 - AI Agent Identity Types
10:53 - Carnival Customer Perspective
12:07 - AI Agent Security Solutions
14:48 - Delegated Agent Controls
16:01 - Autonomous Agent Security
17:04 - Platform Demo: Agent Governance

Key Quotes

0:29 "The ratio is already 109 machines to a single human. It's going to be 110 soon. And with the fast adoption of AI agents, it's growing faster than ever before."
4:26 "If an attacker steals a secret, he is instantly trusted. This is a fundamental identity problem."
5:07 "Those identities that we're issuing, they're ephemeral. They live for minutes, even seconds. And in case the identity is compromised by an attacker somehow, it is already gone."
11:11 "We've pulled back over 2,000 AI agents between Copilot and Bedrock. I knew there was going to be shadow IT. I knew it without a doubt. The fact that it was that bad, though, was an eye opener."
14:11 "A couple of weeks ago, we've entered into a definitive agreement to acquire Portkey.AI, a pioneer in AI gateways."
16:42 "The agent can get the privilege it needs to get the job done, but it never actually sees the secrets. It never touches the keys."

FAQ

How does the platform handle both modern and legacy infrastructure?

The platform uses an 'any to any to any' model that allows any workload — from mainframes to AI agents — to use any access method (secrets, tokens, certificates) to connect to any target (cloud or on-premises), eliminating the need to choose between modernization and security.

What's the difference between delegated and autonomous AI agents from a security perspective?

Delegated agents borrow human permissions to perform tasks on behalf of users, requiring audit separation and fine-grained policies to track what the agent did versus the user. Autonomous agents operate independently with their own privileges and secrets, requiring SPIFFE-based workload identities with continuous attestation and just-in-time credential access to prevent over-provisioning.


Categories:
  • » Cybersecurity » Application Security
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • AI & Machine Learning
  • Zero Trust
  • Cloud Security
  • DevSecOps
  • Technical Deep Dive
  • Machine Identity Security
  • AI Agent Governance
  • SPIFFE Authentication
  • Secrets Management
  • Zero Trust Architecture
  • Ephemeral Credentials
  • CI
  • CD Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Palo Alto Networks: Securing Machine Identities and AI Agents at Scale

              Industry Events (Sponsor Hosted)

              • Aug
                06

                Safeguarding Sensitive Data in the Age of AI Platforms

                08/06/202604:00 AM ET
                • Aug
                  06

                  AI Agents Transforming Identity Attack Tactics and Speed

                  08/06/202602:00 PM ET
                  • Aug
                    13

                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                    08/13/202612:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Age of AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-age-of-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      AI Agents Transforming Identity Attack Tactics and Speed
                      https://www.truthinit.com/index.php/channel/2064/ai-agents-transforming-identity-attack-tactics-and-speed/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version