Okta Targets Identity Security Expansion
Okta plans to acquire Permiso Security to bolster its identity threat detection capabilities within multi-cloud environments.
In a strategic maneuver aimed at deepening its influence within security operations centers, Okta has announced its intent to acquire Permiso Security. The deal marks a pivot for the identity provider, as it looks to move beyond its traditional management roots into the specialized field of identity threat detection and response (ITDR).
Broadening Identity Security Scope
By integrating Permiso’s technology, Okta aims to address visibility gaps that persist across complex, multi-cloud architectures. The acquisition focuses on monitoring threats that span human users, non-human service accounts, and the increasing volume of agentic identities that perform autonomous tasks within modern enterprise networks. The goal is to provide a comprehensive security fabric that offers runtime detection across all identity types.
“We’re thrilled to welcome Permiso to Okta as we help companies secure their agentic enterprises where humans, applications, service accounts, and AI agents work together.”
— Ely Kahn, Chief Product Officer at Okta
Kahn also highlighted that the acquisition brings “proven identity threat detection and response capabilities, and an incredible threat research and security team that will advance Okta’s threat detection and prevention capabilities.”
Strengthening Security Operations
Beyond the technical integration, the move signals a desire to establish a firmer presence within the enterprise Security Operations Center. The deal will see the incorporation of P0 Labs, the threat research division of Permiso, into Okta’s own research operations. This transition is expected to provide deeper post-authentication visibility into suspicious activities, allowing for enhanced threat hunting and more robust detection logic across the entire identity lifecycle. By unifying identity threat detection with posture management, Okta intends to create a singular, streamlined security offering.
Transaction and Financial Outlook
The acquisition remains subject to standard closing conditions and is anticipated to finalize in the third quarter of Okta’s fiscal year 2027. Despite the ongoing consolidation in the security sector, Okta has confirmed that the financial terms of the agreement were not disclosed and that the purchase will not alter the financial guidance provided by the company on May 27, 2026.
Implications for Enterprise Security
For organizations already utilizing Okta’s ecosystem, this acquisition suggests a shift toward more integrated security operations. As identity becomes the primary perimeter in cloud-native environments, the ability to correlate suspicious behavior with specific service or AI agent identities could become a critical requirement for CISOs. This transition could mean that businesses will eventually rely on a more unified platform to manage both access control and active threat mitigation, potentially reducing the need to maintain fragmented security tooling for identity-specific monitoring.
Sources
- SecurityWeek Original source
- Permiso Security Also reporting
Continue Reading
Critical RCE Flaw Found in Azure Cosmos DB
A critical vulnerability in Azure Cosmos DB allows unauthorized remote code execution, earning a maximum CVSS score of 10.
OpenClaw Dashboard Critical XSS Flaw Found
A stored cross-site scripting vulnerability in OpenClaw Dashboard v3.0.0 allows unauthenticated attackers to hijack administrator sessions.
Critical AWS Amplify Studio Flaw Found
A critical input validation vulnerability in AWS Amplify Studio allows authenticated users to execute arbitrary JavaScript code during component rendering.