ChannelLife Ireland - Industry insider news for technology resellers
Ireland
Portnox adds AI agent access controls with Defender

Portnox adds AI agent access controls with Defender

Tue, 18th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Portnox has added controls that let enterprises block or revoke network access for risky AI agents. The update includes a new integration with Microsoft Defender.

The addition completes an enforcement layer alongside existing integrations with CrowdStrike and SentinelOne. It is designed to help security teams act automatically when an AI agent or other non-human identity shows elevated risk, suspicious activity, or a change in device posture.

Under the setup, signals from those security platforms feed into Portnox access policies at the network layer. Organisations can then block, quarantine, or revoke access based on pre-set rules instead of waiting for a security analyst to respond manually.

The controls apply to all identities, including human users and non-human identities such as AI agents. Portnox positions the approach as a way to extend zero trust access controls to software-driven identities that are increasingly used inside corporate systems.

AI access

AI agents are taking on a wider role in enterprise environments, where they can authenticate to applications and infrastructure, access data, and carry out tasks across multiple systems. That creates a new security problem for companies that have traditionally managed access around employees and managed devices.

According to figures Portnox cited from Venture Beat's Q2 2026 Research Report, 54% of enterprises have experienced a confirmed agent security incident, while 69% said they share credentials across AI agents. Those practices can leave organisations with limited oversight of what an agent is accessing and whether its behaviour has changed.

Many businesses still manage non-human identities with static credentials, shared accounts, and broad permissions. As a result, security teams can struggle to determine in real time whether access should continue once a risk signal appears elsewhere in the environment.

"AI agents are becoming active participants in the enterprise, but many organizations are still relying on access models built for human users and managed devices," said Denny LeCompte, Chief Executive Officer at Portnox.

"Every identity that can connect, access data, or act must be continuously verified and governed. Portnox gives organizations the ability to immediately restrict access when trust changes, without waiting for an AI agent to create a larger security incident," LeCompte said.

Enforcement layer

Portnox says its system works as an independent enforcement point between threat detection and access control. In practice, a threat or posture signal raised by CrowdStrike, SentinelOne, or Microsoft Defender can trigger an automated decision on whether a device, user, or AI agent should remain connected.

Portnox describes the process in three steps: detection of elevated risk, evaluation of that signal against policy, and enforcement through blocking, quarantining, or revoking access. The emphasis is on acting at the network layer even if an identity platform has not yet updated or removed permissions.

That distinction matters because identity and privileged access management systems often govern who or what should have access, but do not always provide an immediate control point for cutting off live connectivity. Portnox is seeking to fill that gap by tying risk intelligence directly to access enforcement.

Garrett Gross, Field CISO at Portnox, said many organisations are not struggling to spot unusual behaviour but to respond quickly enough to stop further access.

"The gap we keep seeing is between knowing something's wrong and actually doing something about it," Gross said.

"A lot of tools can tell you an AI agent is behaving strangely. Very few can act on that at the network layer without waiting on a human to approve a ticket. That's the piece we're closing," he said.

Visibility and control

Beyond immediate access restrictions, Portnox says the system gives security and IT teams more visibility into how AI identities are being used. That includes records of which identity connected, when and where it connected, what it was authorised to access, and which policy determined the outcome.

The controls can also help limit lateral movement by compromised or over-privileged AI identities. By enforcing scoped access rules, organisations can reduce the chance that a single compromised agent can move widely across networks, applications, and infrastructure.

The broader challenge for enterprise security teams is that AI agents can operate continuously and autonomously, often much faster than a human operator can intervene. That has pushed vendors across identity, endpoint, and network security to adapt tools originally built around staff logins and company-issued hardware.

Portnox's latest update reflects that shift, as non-human identities become a more prominent part of access governance. Its aim is to give organisations a direct way to sever network access when the risk attached to an AI agent changes.