How Does CrowdStrike Agentic IdP Establish Continuous Identity?
According to the company’s press release, “Agentic IdP establishes every agent as a trusted identity, brokers only the access needed for as long as needed and ties every action back to the human or system behind it. This is the foundation that makes continuous identity possible.”
“Securing AI agents demands solutions built for how they operate,” said Scott Kriz, general manager of continuous identity at CrowdStrike. “Continuous Identity modernized identity security for the agentic era, but you cannot continuously authorize an identity you were never able to establish, and traditional identity providers break the moment an agent acts on its own. Agentic IdP is the identity provider for AI agents.”
“A lot of the concepts that exist around identity are different for agents because they operate at such machine speed,” said Kriz, speaking with BizTech during CrowdStrike Fal.Con. “They don’t have boundaries, and they often inherit the ability to get to things that their creators granted them.”
DISCOVER: Find out how mature your security posture is with a self-assessment.
Agentic Identity and Access Should Be Task-Based
As Sentonas explained in his keynote, “We now have the ability to give people one-time access, but importantly, to remove it and give access on demand, to give access when they need it, access by role type, access to carry out a specific task and to make sure that you remove all standing privilege.”
Kriz pointed out some key partnerships in refining identity-based access. “We’ve integrated with identity providers such as Okta and Microsoft Entra on giving the ability for certain users to get access to infrastructure. Being able to rightsize that access to a specific role based on business context is really important for humans.”
But while it’s necessary to restrict access for human users, it’s becoming even more important to do the same for nonhuman identities. “What happens when the agent can get to your AWS environment?” Kriz asked. CrowdStrike has developed a way to issue tokens — for humans and agents alike — for specific tasks based on business context.
Kriz said these short-lived tokens have already been in use for a while under a part of the Falcon platform called Falcon Privileged Access. “It started out as really just access to Entra, and now we’re expanding it. So, in the next quarter, we’ll be adding GitHub. We’ll be adding Salesforce. We’ll be adding context from ticketing systems like ServiceNow and Jira,” which, he said, would give companies the ability to justify or deny access as soon as a ticket closes, depending on the context.
