AI agent security and identity platforms compared
SHORT ANSWER
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
Ranking
| Rank | Product | Total | Best for |
|---|---|---|---|
| 1 | Okta | 7.8 / 10 | Teams already on Okta that want agent identity from the same vendor |
| 2 | NewCore | 7.5 / 10 | Control over each agent call: no standing credentials, per-call policy, human approval |
| 3 | Silverfort | 7.2 / 10 | Finding agents across identity providers and clouds, then blocking actions inline |
| 4 | Aembit | 7.1 / 10 | Keeping credentials out of agents entirely, with a free tier to start |
| 5 | Microsoft Entra | 7.0 / 10 | Microsoft estates that want agents under Entra ownership and Conditional Access |
How the scores are weighted
- c1 No standing credentials for agents 20%
- c2 Per-call authorization 20%
- c3 Human accountability and approval 15%
- c4 Finding agents you did not register 15%
- c5 Standards and ecosystem 15%
- c6 Maturity and buying clarity 15%
Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.
Scorecard
| Criterion | Okta7.8 / 10 | NewCore7.5 / 10 | Silverfort7.2 / 10 | Aembit7.1 / 10 | Microsoft Entra7.0 / 10 |
|---|---|---|---|---|---|
| c1No standing credentials for agents20%Does the agent receive short-lived, scoped credentials instead of holding a long-lived secret? | 8Okta for AI Agents issues "dynamic, least-privilege tokens" in place of static API keys; Agent SSO with short-lived tokens was listed as generally available in September 2026. Source: Okta: Secure AI · Okta newsroom, 22 Sep 2026 | 9Highest in setAgent Guardian issues "scoped, short-lived credentials on demand" and states the agent never holds the provider's standing credential. Source: NewCore: Agent Guardian | 6Gap in public materialLowest in setThe agent page covers discovery, binding and runtime decisions; issuing short-lived credentials to agents is not described. Source: Silverfort: AI agent security | 9Highest in setStates that agents "never hold direct credentials"; Aembit mints and exchanges credentials at request time. Source: Aembit: IAM for agentic AI | 7Gap in public materialAgents get their own identities, service principals and OAuth flows. A short-lived-by-default credential model is not stated on the overview page. Source: Microsoft Learn: Entra Agent ID |
| c2Per-call authorization20%Is each tool call or operation checked against policy at the moment it runs? | 7Okta says it enforces policy "at every tool call"; its Agent Gateway was announced on 22 September 2026 as planned for Q3 2026 (https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/). Source: Okta: Secure AI · Okta newsroom, 22 Sep 2026 | 9Highest in setEach call is evaluated "at the operation level" against policy. Source: NewCore: Agent Guardian | 8An MCP gateway receives every tool call first and returns an approve or block decision before execution. Source: Silverfort: AI agent security | 7Every MCP request is logged with a policy decision; conditional access uses runtime context. Source: Aembit: IAM for agentic AI · Aembit | 6Gap in public materialLowest in setConditional Access and ID Protection apply to agents. These act at sign-in and token issuance; per-tool-call checks are not described. Source: Microsoft Learn: Entra Agent ID |
| c3Human accountability and approval15%Is every agent tied to a responsible person, and can a risky action wait for human approval? | 7Gap in public materialLowest in setTreats the agent as a principal with delegation from the user and streams access decisions to a SIEM. A human approval step is not described on the page reviewed. Source: Okta: Secure AI | 9Highest in setCalls can be routed for human approval by policy, and every action is tied to the agent, the accountable human or team, and the policy. Source: NewCore: Agent Guardian | 7Gap in public materialLowest in setBinds each agent to a human identity and maps actions to responsible people. A human approval step is not described. Source: Silverfort: AI agent security | 7Gap in public materialLowest in setBlended Identity combines the agent's identity with the human operating it. A human approval step is not described. Source: Aembit: IAM for agentic AI | 7Lowest in setEvery agent identity has owners and sponsors, and agents can be governed with access packages. Source: Microsoft Learn: Entra Agent ID |
| c4Finding agents you did not register15%Can the product surface agents that were never registered with IT? | 8Surfaces unsanctioned agents and registers them in a central directory. Source: Okta: Secure AI | 7Identity Discovery lists AI agents in the same graph as people and apps; sources named are Okta, AWS, Microsoft, BambooHR, Salesforce and Google. Source: NewCore: Identity Discovery | 9Highest in setDiscovers sanctioned and rogue agents through read-only APIs across Entra ID, Okta, AWS, Azure and GCP. Source: Silverfort: AI agent security | 4Gap in public materialLowest in setDiscovery of unregistered agents is not described on the pages reviewed. Source: Aembit: IAM for agentic AI | 6Gap in public materialRegisters agents built on Microsoft and supported third-party platforms; discovery of unregistered agents is not described on the pages reviewed. Source: Microsoft Learn: Entra Agent ID · Microsoft Learn: agent identities for AI agents |
| c5Standards and ecosystem15%Published protocol support and breadth of what the product already connects to. | 9Highest in setPublishes the Cross App Access protocol and an integration network of 8,000+ pre-built integrations. Source: Okta: Secure AI · Okta Integration Network | 6Lowest in setTwo access paths are published, an MCP gateway and an OAuth-based Enterprise Managed Authorization flow. No integration count or named agent list is published. Source: NewCore: Agent Guardian | 7Works with Entra ID, Okta and the three main clouds through an MCP gateway and SSO through your identity provider. Source: Silverfort: AI agent security | 7MCP Identity Gateway runs as a VM in your environment; names Claude, Microsoft Copilot Studio and Gemini CLI. Source: Aembit: IAM for agentic AI | 9Highest in setGenerally available for all Entra customers, with OAuth protocols for agents and third-party agent configuration. Source: Microsoft Learn: agent identities for AI agents · Microsoft Learn: Entra Agent ID |
| c6Maturity and buying clarity15%Time in market, published pricing or free tier, and general availability status. | 8Gap in public materialHighest in setOkta for AI Agents is sold as an add-on to published Workforce Identity plans; the add-on price itself is not published. Source: Okta pricing | 4Lowest in setLaunched in June 2026. No pricing and no named customers are published. Source: NewCore home page · NewCore launch release (PR Newswire) | 6Established identity protection vendor. No pricing or launch date for the agent product is published. | 8Highest in setOffers a free-forever tier and states SOC 2 Type II and ISO 27001:2022. Source: Aembit: IAM for agentic AI · Aembit | 7Gap in public materialGenerally available; extended security features need Microsoft Agent 365. Pricing for those features is not on the pages reviewed. |
Okta
7.8 / 10
c1 · 20%
No standing credentials for agents
8
Okta for AI Agents issues "dynamic, least-privilege tokens" in place of static API keys; Agent SSO with short-lived tokens was listed as generally available in September 2026.
Source: Okta: Secure AI · Okta newsroom, 22 Sep 2026
c2 · 20%
Per-call authorization
7
Okta says it enforces policy "at every tool call"; its Agent Gateway was announced on 22 September 2026 as planned for Q3 2026 (https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/).
Source: Okta: Secure AI · Okta newsroom, 22 Sep 2026
c3 · 15%
Human accountability and approval
7Gap in public materialLowest in set
Treats the agent as a principal with delegation from the user and streams access decisions to a SIEM. A human approval step is not described on the page reviewed.
Source: Okta: Secure AI
c4 · 15%
Finding agents you did not register
8
Surfaces unsanctioned agents and registers them in a central directory.
Source: Okta: Secure AI
c5 · 15%
Standards and ecosystem
9Highest in set
Publishes the Cross App Access protocol and an integration network of 8,000+ pre-built integrations.
Source: Okta: Secure AI · Okta Integration Network
c6 · 15%
Maturity and buying clarity
8Gap in public materialHighest in set
Okta for AI Agents is sold as an add-on to published Workforce Identity plans; the add-on price itself is not published.
Source: Okta pricing
NewCore
7.5 / 10
c1 · 20%
No standing credentials for agents
9Highest in set
Agent Guardian issues "scoped, short-lived credentials on demand" and states the agent never holds the provider's standing credential.
Source: NewCore: Agent Guardian
c2 · 20%
Per-call authorization
9Highest in set
Each call is evaluated "at the operation level" against policy.
Source: NewCore: Agent Guardian
c3 · 15%
Human accountability and approval
9Highest in set
Calls can be routed for human approval by policy, and every action is tied to the agent, the accountable human or team, and the policy.
Source: NewCore: Agent Guardian
c4 · 15%
Finding agents you did not register
7
Identity Discovery lists AI agents in the same graph as people and apps; sources named are Okta, AWS, Microsoft, BambooHR, Salesforce and Google.
Source: NewCore: Identity Discovery
c5 · 15%
Standards and ecosystem
6Lowest in set
Two access paths are published, an MCP gateway and an OAuth-based Enterprise Managed Authorization flow. No integration count or named agent list is published.
Source: NewCore: Agent Guardian
c6 · 15%
Maturity and buying clarity
4Lowest in set
Launched in June 2026. No pricing and no named customers are published.
Source: NewCore home page · NewCore launch release (PR Newswire)
Silverfort
7.2 / 10
c1 · 20%
No standing credentials for agents
6Gap in public materialLowest in set
The agent page covers discovery, binding and runtime decisions; issuing short-lived credentials to agents is not described.
Source: Silverfort: AI agent security
c2 · 20%
Per-call authorization
8
An MCP gateway receives every tool call first and returns an approve or block decision before execution.
Source: Silverfort: AI agent security
c3 · 15%
Human accountability and approval
7Gap in public materialLowest in set
Binds each agent to a human identity and maps actions to responsible people. A human approval step is not described.
Source: Silverfort: AI agent security
c4 · 15%
Finding agents you did not register
9Highest in set
Discovers sanctioned and rogue agents through read-only APIs across Entra ID, Okta, AWS, Azure and GCP.
Source: Silverfort: AI agent security
c5 · 15%
Standards and ecosystem
7
Works with Entra ID, Okta and the three main clouds through an MCP gateway and SSO through your identity provider.
Source: Silverfort: AI agent security
c6 · 15%
Maturity and buying clarity
6
Established identity protection vendor. No pricing or launch date for the agent product is published.
Aembit
7.1 / 10
c1 · 20%
No standing credentials for agents
9Highest in set
States that agents "never hold direct credentials"; Aembit mints and exchanges credentials at request time.
Source: Aembit: IAM for agentic AI
c2 · 20%
Per-call authorization
7
Every MCP request is logged with a policy decision; conditional access uses runtime context.
Source: Aembit: IAM for agentic AI · Aembit
c3 · 15%
Human accountability and approval
7Gap in public materialLowest in set
Blended Identity combines the agent's identity with the human operating it. A human approval step is not described.
Source: Aembit: IAM for agentic AI
c4 · 15%
Finding agents you did not register
4Gap in public materialLowest in set
Discovery of unregistered agents is not described on the pages reviewed.
Source: Aembit: IAM for agentic AI
c5 · 15%
Standards and ecosystem
7
MCP Identity Gateway runs as a VM in your environment; names Claude, Microsoft Copilot Studio and Gemini CLI.
Source: Aembit: IAM for agentic AI
c6 · 15%
Maturity and buying clarity
8Highest in set
Offers a free-forever tier and states SOC 2 Type II and ISO 27001:2022.
Source: Aembit: IAM for agentic AI · Aembit
Microsoft Entra
7.0 / 10
c1 · 20%
No standing credentials for agents
7Gap in public material
Agents get their own identities, service principals and OAuth flows. A short-lived-by-default credential model is not stated on the overview page.
Source: Microsoft Learn: Entra Agent ID
c2 · 20%
Per-call authorization
6Gap in public materialLowest in set
Conditional Access and ID Protection apply to agents. These act at sign-in and token issuance; per-tool-call checks are not described.
Source: Microsoft Learn: Entra Agent ID
c3 · 15%
Human accountability and approval
7Lowest in set
Every agent identity has owners and sponsors, and agents can be governed with access packages.
Source: Microsoft Learn: Entra Agent ID
c4 · 15%
Finding agents you did not register
6Gap in public material
Registers agents built on Microsoft and supported third-party platforms; discovery of unregistered agents is not described on the pages reviewed.
Source: Microsoft Learn: Entra Agent ID · Microsoft Learn: agent identities for AI agents
c5 · 15%
Standards and ecosystem
9Highest in set
Generally available for all Entra customers, with OAuth protocols for agents and third-party agent configuration.
Source: Microsoft Learn: agent identities for AI agents · Microsoft Learn: Entra Agent ID
c6 · 15%
Maturity and buying clarity
7Gap in public material
Generally available; extended security features need Microsoft Agent 365. Pricing for those features is not on the pages reviewed.
What is AI agent security?
AI agent security is the set of controls that decide what an AI agent can reach, which credentials it uses to get there, and who answers for what it does. The difference from securing a normal application is that an agent chooses its own next step, so the check has to happen at the moment of each action rather than once at deployment.
The OWASP GenAI Security Project runs an Agentic Security Initiative and publishes the OWASP Top 10 for Agentic Applications, released in December 2025. It is the most widely cited public list of agent-specific risks.
What is an AI agent identity?
An AI agent identity is an account that belongs to the agent itself, separate from the person who started it and from the service account of the platform it runs on. With its own identity, an agent can be given its own permissions, logged under its own name and switched off without disabling anyone else.
Vendors split agents into types. NewCore names three: agents acting on behalf of a person, agents with delegated authority, and autonomous agents. Microsoft Entra Agent ID models agents as agent identities created from blueprints, each with owners and sponsors. Okta treats the agent as a principal in its own right, with delegation from the user it works for. The term agentic IAM is used for this extension of identity and access management to agents.
How do you secure AI agents in practice?
- Give every agent its own identity and a named human owner.
- Replace long-lived API keys with short-lived, scoped credentials issued per task.
- Check each tool call against policy when it happens, not only at sign-in.
- Route high-risk actions to a person for approval.
- Log each action with the agent, the owner, the policy and the outcome, and send it to your SIEM.
- Look for agents that were never registered, because the unregistered ones carry the most risk.
The six criteria in the scorecard follow this list.
How does AI agent authentication work?
Most products use OAuth. The agent obtains a token for a specific resource, and the resource checks that the token was issued for it. The MCP authorization specification follows the same model: MCP servers act as OAuth 2.1 resource servers, clients must name the target server with a resource parameter, and servers must reject tokens issued for anyone else.
Around that core, vendors add their own layers. Okta publishes Cross App Access, a protocol for letting one app act in another on a user's behalf. NewCore offers an OAuth-based Enterprise Managed Authorization flow that issues scoped, time-bound tokens. Aembit mints and exchanges credentials at request time so the agent never holds them.
What does AI access control look like per call?
Per-call access control means the policy engine sees each request: which tool, which operation, which data, on whose behalf. NewCore evaluates each call at the operation level. Silverfort's MCP gateway returns an approve or block decision before a tool call runs. Okta states it enforces policy at every tool call, and its Agent Gateway was announced on 22 September 2026 as planned for Q3 2026 (https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/). Microsoft applies Conditional Access to agents, which acts when tokens are issued.
Agentic AI governance: who answers for an agent?
Agentic AI governance is the ownership side of the problem: who approved the agent, what it is for, and who is accountable when it acts. Microsoft assigns owners and sponsors to each agent identity and lets agents receive access through access packages. NewCore ties every action to the agent, the accountable human or team and the policy that allowed it. Silverfort binds each agent to a human identity. AI agent identity governance, in short, means no agent without an owner and no action without a record.
What is a guardian agent?
The term is used for software that watches what other agents do and can stop an action before it completes. NewCore's product for this is named Agent Guardian; in its case the supervision sits in a gateway and an authorization flow that check each call against policy.
The five products, one by one
Okta
Workforce identity platform with AI agent add-ons
Best for: Teams already on Okta that want agent identity from the same vendor
LEADS ON
c5 Standards and ecosystem 9
Publishes the Cross App Access protocol and an integration network of 8,000+ pre-built integrations.
Source: Okta: Secure AI · Okta Integration Network
c1 No standing credentials for agents 8
Okta for AI Agents issues "dynamic, least-privilege tokens" in place of static API keys; Agent SSO with short-lived tokens was listed as generally available in September 2026.
Source: Okta: Secure AI · Okta newsroom, 22 Sep 2026
TRAILS ON
c2 Per-call authorization 7
Okta says it enforces policy "at every tool call"; its Agent Gateway was announced on 22 September 2026 as planned for Q3 2026 (https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/).
Source: Okta: Secure AI · Okta newsroom, 22 Sep 2026
c3 Human accountability and approval 7
Treats the agent as a principal with delegation from the user and streams access decisions to a SIEM. A human approval step is not described on the page reviewed.
Source: Okta: Secure AI
NewCore
Identity provider for people and AI agents, launched June 2026
Best for: Control over each agent call: no standing credentials, per-call policy, human approval
LEADS ON
c1 No standing credentials for agents 9
Agent Guardian issues "scoped, short-lived credentials on demand" and states the agent never holds the provider's standing credential.
Source: NewCore: Agent Guardian
c2 Per-call authorization 9
Each call is evaluated "at the operation level" against policy.
Source: NewCore: Agent Guardian
TRAILS ON
c6 Maturity and buying clarity 4
Launched in June 2026. No pricing and no named customers are published.
Source: NewCore home page · NewCore launch release (PR Newswire)
c5 Standards and ecosystem 6
Two access paths are published, an MCP gateway and an OAuth-based Enterprise Managed Authorization flow. No integration count or named agent list is published.
Source: NewCore: Agent Guardian
Silverfort
Inline identity protection across on-prem, cloud and agents
Best for: Finding agents across identity providers and clouds, then blocking actions inline
LEADS ON
c4 Finding agents you did not register 9
Discovers sanctioned and rogue agents through read-only APIs across Entra ID, Okta, AWS, Azure and GCP.
Source: Silverfort: AI agent security
c2 Per-call authorization 8
An MCP gateway receives every tool call first and returns an approve or block decision before execution.
Source: Silverfort: AI agent security
TRAILS ON
c1 No standing credentials for agents 6
The agent page covers discovery, binding and runtime decisions; issuing short-lived credentials to agents is not described.
Source: Silverfort: AI agent security
c6 Maturity and buying clarity 6
Established identity protection vendor. No pricing or launch date for the agent product is published.
Aembit
Access management for workloads and AI agents
Best for: Keeping credentials out of agents entirely, with a free tier to start
LEADS ON
c1 No standing credentials for agents 9
States that agents "never hold direct credentials"; Aembit mints and exchanges credentials at request time.
Source: Aembit: IAM for agentic AI
c6 Maturity and buying clarity 8
Offers a free-forever tier and states SOC 2 Type II and ISO 27001:2022.
Source: Aembit: IAM for agentic AI · Aembit
TRAILS ON
c4 Finding agents you did not register 4
Discovery of unregistered agents is not described on the pages reviewed.
Source: Aembit: IAM for agentic AI
c2 Per-call authorization 7
Every MCP request is logged with a policy decision; conditional access uses runtime context.
Source: Aembit: IAM for agentic AI · Aembit
Microsoft Entra
Microsoft's identity family: Entra ID, Entra Agent ID
Best for: Microsoft estates that want agents under Entra ownership and Conditional Access
LEADS ON
c5 Standards and ecosystem 9
Generally available for all Entra customers, with OAuth protocols for agents and third-party agent configuration.
Source: Microsoft Learn: agent identities for AI agents · Microsoft Learn: Entra Agent ID
c1 No standing credentials for agents 7
Agents get their own identities, service principals and OAuth flows. A short-lived-by-default credential model is not stated on the overview page.
Source: Microsoft Learn: Entra Agent ID
TRAILS ON
c2 Per-call authorization 6
Conditional Access and ID Protection apply to agents. These act at sign-in and token issuance; per-tool-call checks are not described.
Source: Microsoft Learn: Entra Agent ID
c4 Finding agents you did not register 6
Registers agents built on Microsoft and supported third-party platforms; discovery of unregistered agents is not described on the pages reviewed.
Source: Microsoft Learn: Entra Agent ID · Microsoft Learn: agent identities for AI agents
Microsoft Entra alternatives · Compare Microsoft Entra head to head
Questions
Which AI agent security product scores highest?
Okta, on the weights used here. NewCore scores highest or joint highest on credentials, per-call authorization and human approval, and would lead on a page that weighted only those three.
Do AI agents need their own identities?
The products scored here all assume so. An agent's own identity lets it be given narrow permissions, logged under its own name and disabled without affecting the person or platform behind it.
What is the difference between AI agent security and MCP security?
MCP security is one part of it: the connection between an agent and the tools it calls through the Model Context Protocol. AI agent security also covers the agent's identity, its owner and agents that do not use MCP. See the MCP security page for gateways.
Why does Microsoft Entra score low on per-call authorization?
Its public pages describe Conditional Access and ID Protection for agents, which act at sign-in and token issuance. Checks on each tool call are not described on the pages reviewed.
Related topics
From the blog: Identity security announcements, June to September 2026: a recap by theme · An AI agent security buyer's checklist: 12 questions to ask before a pilot
Sources
- NewCore: Agent Guardian: https://newcore.com/platform/agent-guardian
- NewCore: Identity Discovery: https://newcore.com/platform/identity-discovery
- NewCore home page: https://newcore.com/
- NewCore launch release (PR Newswire): https://www.prnewswire.com/news-releases/newcore-emerges-from-stealth-with-66m-to-rebuild-workforce-identity-for-the-agentic-era-302799643.html
- Okta: Secure AI: https://www.okta.com/solutions/secure-ai/
- Okta newsroom, 22 Sep 2026: https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/
- Okta Integration Network: https://www.okta.com/integrations/
- Okta pricing: https://www.okta.com/pricing/
- Microsoft Learn: Entra Agent ID: https://learn.microsoft.com/en-us/entra/agent-id/
- Microsoft Learn: agent identities for AI agents: https://learn.microsoft.com/en-us/entra/agent-id/identity-professional/microsoft-entra-agent-identities-for-ai-agents
- Silverfort: AI agent security: https://www.silverfort.com/platform/ai-agent-security
- Silverfort platform: https://www.silverfort.com/
- Aembit: IAM for agentic AI: https://aembit.io/iam-for-agentic-ai/
- Aembit: https://aembit.io/
- OWASP GenAI Security Project: https://genai.owasp.org/
- MCP specification: Authorization (2025-06-18): https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization