Portnox adds Microsoft Defender integration to police AI agent access
Portnox adds Microsoft Defender integration to police AI agents, SiliconANGLE reported.
Portnox had previously connected CrowdStrike and SentinelOne. Now any of the three endpoint protection platforms can trigger an access decision. If a threat is reported or a device falls out of compliance, the Portnox policy engine can cut the connection, quarantine the identity, or revoke access entirely, depending on the customer's rules. Employees are subject to the same treatment.
These nonhuman identities behave differently from human employees. AI agents authenticate to systems, retrieve sensitive data, and act on their own at machine speed. Yet many enterprises still issue them static credentials, shared accounts, and standing permissions, verifying identity only once at login. Security teams are left without visibility into what an agent is touching or whether its behavior has changed.
The problem has already produced incidents. VentureBeat research cited by SiliconANGLE found that 54% of enterprises had a confirmed agent security incident in the second quarter, and 69% admitted to sharing credentials across their agents.
'AI agents are becoming active participants in the enterprise, but many organizations are still relying on access models built for human users and managed devices,' said Portnox Chief Executive Denny LeCompte. 'Every identity that can connect, access data or act must be continuously verified and governed. Portnox gives organizations the ability to immediately restrict access when trust changes, without waiting for an AI agent to create a larger security incident.'
Portnox describes the offering as a kill switch at the network layer. Identity and privileged access management tools determine which resources an agent should reach; cutting the connection is a separate job that Portnox says can be done before an identity provider revokes anything. The process runs in three steps: an endpoint platform detects the risk, the policy engine evaluates the signal against access rules in real time, and enforcement follows automatically.
Field Chief Information Security Officer Garrett Gross said the gap Portnox keeps encountering is 'between knowing something's wrong and actually doing something about it.' Many products can report that an agent is behaving strangely, he said, but far fewer can act at the network layer without waiting for someone to approve a ticket.
The system also produces an audit trail showing which identity connected, when and from where, what it was cleared to access, and which policy made the decision.
Portnox is a venture capital-backed startup that has raised approximately $59.5 million, including a $37.5 million Series B round led by Updata Partners in April 2025.