Sep 09 2026
Security

CrowdStrike Fal.Con 2026: Confronting the New Challenges of Identity in the Agentic Era

With artificial intelligence agents being created and deployed at the enterprise level, managing identities and access becomes more complex and increasingly critical to cybersecurity.

Artificial intelligence is changing the needs of organizations to restrict and control access within their environments because of an ever-increasing number of identities, both human and nonhuman. AI agents are adding new wrinkles to the challenge of identity, and they’re forcing organizations to seek out new tools for assistance.

At last week’s CrowdStrike Fal.Con, CrowdStrike introduced its Agentic Identity Provider (IdP). As the cybersecurity provider noted in a Sept. 2 press release, “Identity is the front line of modern attacks, and AI agents accelerate the threat at scale. They execute code, access systems, and move data with real credentials, at machine speed, with no one watching. Before they can be continuously authorized, they must first be established as trusted identities, something traditional identity providers were never built to do.”

Speaking at a Sept. 3 keynote session, CrowdStrike President Michael Sentonas told attendees, “Every agent has an identity, and in most cases, it’s an overprivileged identity. And in too many cases, it inherits the human permissions, and you are all deploying them faster than you can govern them.”

Sentonas emphasized the importance of asking who or what created each agent in your environment. But that’s just the tip of the iceberg in establishing identity and authorizing access. “Who is it shared with? What third-party systems can it access? What permissions does it have, and where can it go? The challenge isn’t granting access to that agent once; it’s knowing what it should be allowed to do at every moment it’s running and every step. And we have to make a big change here. Trust cannot stop at authentication.”

Click the banner below to read the recent CDW Cybersecurity Research Report. 

 

How Does CrowdStrike Agentic IdP Establish Continuous Identity?

According to the company’s press release, “Agentic IdP establishes every agent as a trusted identity, brokers only the access needed for as long as needed and ties every action back to the human or system behind it. This is the foundation that makes continuous identity possible.”

“Securing AI agents demands solutions built for how they operate,” said Scott Kriz, general manager of continuous identity at CrowdStrike. “Continuous Identity modernized identity security for the agentic era, but you cannot continuously authorize an identity you were never able to establish, and traditional identity providers break the moment an agent acts on its own. Agentic IdP is the identity provider for AI agents.”

“A lot of the concepts that exist around identity are different for agents because they operate at such machine speed,” said Kriz, speaking with BizTech during CrowdStrike Fal.Con. “They don’t have boundaries, and they often inherit the ability to get to things that their creators granted them.”

DISCOVER: Find out how mature your security posture is with a self-assessment.

Agentic Identity and Access Should Be Task-Based

As Sentonas explained in his keynote, “We now have the ability to give people one-time access, but importantly, to remove it and give access on demand, to give access when they need it, access by role type, access to carry out a specific task and to make sure that you remove all standing privilege.”

Kriz pointed out some key partnerships in refining identity-based access. “We’ve integrated with identity providers such as Okta and Microsoft Entra on giving the ability for certain users to get access to infrastructure. Being able to rightsize that access to a specific role based on business context is really important for humans.”

But while it’s necessary to restrict access for human users, it’s becoming even more important to do the same for nonhuman identities. “What happens when the agent can get to your AWS environment?” Kriz asked. CrowdStrike has developed a way to issue tokens — for humans and agents alike — for specific tasks based on business context.

Kriz said these short-lived tokens have already been in use for a while under a part of the Falcon platform called Falcon Privileged Access. “It started out as really just access to Entra, and now we’re expanding it. So, in the next quarter, we’ll be adding GitHub. We’ll be adding Salesforce. We’ll be adding context from ticketing systems like ServiceNow and Jira,” which, he said, would give companies the ability to justify or deny access as soon as a ticket closes, depending on the context.

Michael Sentonas headshot
We have to make a big change here. Trust cannot stop at authentication.”

Michael Sentonas President, CrowdStrike

Establishing Identity Becomes More Complicated With Shadow AI

As organizations encourage their employees to learn AI skills and spin up their own agents, the occurrence of shadow AI has increased, and more vulnerabilities have opened up.

Kriz said he thinks business leaders initially saw agentic AI as a productivity tool, so they’ve been pushing employees to use it before thinking through the important issues of identity, access and governance. “But then you start seeing things that could be existential threats to a company,” Kriz said. “You have to know the identities to be able to manage them, right? And Guardian was the clear first step in doing that.”

And with Agentic IdP, he said, “we can now look at what’s going on. We can catalog it. We can identify it. We can actually prevent activity happening off machines, so you don’t give agents access to things on your machine.”

The next step is securing the actions being taken by agents, Kriz noted: “What happens off the machine? What happens when they’re trying to get to these other resources?” Agentic IdP can establish a clear identity thread throughout.

“I think identity and security have been at odds for a long time,” he added. “Identity is all about reducing friction: Let people get in so they can do their jobs. And security is about stopping people from doing things. And those things have been converging organically.” 
 

Photography by Joe Kuehne
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.