Product1 distinct publisher3 min readUpdated
The access control vendor now takes risk signals from Microsoft Defender, CrowdStrike and SentinelOne to cut an AI agent's connection mid-session. The pitch rests on numbers it did not gather.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
Portnox has added an integration with Microsoft Defender to the access control product it sells for governing AI agents and other nonhuman identities logging in to corporate networks, applications and infrastructure [1][2]. CrowdStrike and SentinelOne were already wired in, and any of the three can now trigger an access decision [2][3].
The mechanics are described in three steps: one of the endpoint platforms detects risk, the Portnox policy engine weighs that signal against the customer's access rules in real time, and enforcement follows automatically [4]. If a threat is reported or a device slips out of compliance, the engine can cut the connection, drop the identity into quarantine, or pull its access entirely, depending on the rules the customer wrote [5]. Employees are subject to the same treatment [6].
The interesting part is what the product design admits. Agents authenticate to systems, pull sensitive data and act on their own, continuously and at machine speed [7], and yet many enterprises still issue them static credentials, shared accounts and standing permissions, then verify identity only once, at login [8]. A one-time check is not governance for something that keeps working after the check. Portnox calls its answer a kill switch at the network layer, and its argument is that identity and privileged access tools decide what an agent ought to reach, while severing the connection is a separate job that can be done before an identity provider has revoked anything [9][10]. That last claim is the company's, and the source material offers no independent latency measurement to support it.
Chief Executive Denny LeCompte said that "every identity that can connect, access data or act must be continuously verified and governed," and that Portnox lets organizations restrict access "when trust changes, without waiting for an AI agent to create a larger security incident" [11]. Field CISO Garrett Gross put the sales case more plainly: the recurring gap is "between knowing something's wrong and actually doing something about it," with plenty of products able to report strange agent behavior and far fewer able to act at the network layer without waiting on ticket approval [12].
The supporting numbers come from research by VentureBeat in the second quarter, cited by Portnox: 54% of enterprises reported a confirmed agent security incident, and 69% admitted to sharing credentials across their agents [13][14]. The credential-sharing figure runs 15 percentage points ahead of the incident figure [15], which is the more useful reading of the pair. The hygiene failure is already more widespread than the detected consequences, meaning the incident rate is a floor rather than a ceiling. Both figures are self-reported and neither was gathered by the vendor citing them.
Buyers should also note where enforcement starts. Because the chain begins with endpoint detection [4], coverage tracks wherever those three vendors have telemetry, which is a real constraint for agents running somewhere an endpoint sensor is not. The compensating deliverable is an audit trail covering which identity connected, when and from where, what it was cleared to reach, and which policy made the call [16].
Portnox has raised approximately $59.5 million, including a $37.5 million Series B led by Updata Partners in April 2025 [17], so roughly 63% of its total funding arrived in that single round [18]. Watch whether customers actually set these policies to revoke rather than alert, and whether rival network access vendors match the Defender hookup.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Portnox describes what it is selling as a kill switch sitting at the network layer.
Portnox argues that identity and privileged access management tools decide what an agent ought to be allowed to reach, while cutting the connection is a separate job that it can do before an identity provider has gotten around to revoking anything.
Cloud-native access control company Portnox unveiled expanded capabilities aimed at governing AI agents and other nonhuman identities logging in to corporate networks, applications and infrastructure.
The new piece of the announcement is an integration with Microsoft Corp.'s Defender.
Portnox had already integrated CrowdStrike Holdings Inc. and SentinelOne Inc., and any of the three can now trigger an access decision.
The mechanics run in three steps: one of the three endpoint platforms detects the risk, the Portnox policy engine weighs that signal against the customer's access rules in real time, and enforcement follows automatically.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-sourced account, no independent verification
The cluster contains exactly one article, built from a vendor announcement and two vendor executives' quotes. Capability descriptions are internally coherent and specific about integrations, enforcement actions and audit fields, which supports the existence of the release. Nothing else is independently checked: no test, no customer, no third-party comparison, and the two quantitative claims used to size the problem are relayed from a study absent from the cluster and stripped of methodology.
Availability announced, no usage evidence
The only adoption signal is the release itself plus the pre-existing CrowdStrike and SentinelOne integrations, which establish that the capability exists and has more than one signal source wired in. There are no named customers, deployment counts, pilot outcomes, seat or agent volumes, or revenue attach figures anywhere in the supplied material, so real-world uptake of the agent-governance capabilities is essentially unevidenced rather than shown to be low.
Kill-switch framing outruns the evidence supplied
The pitch asserts immediate, automatic, machine-speed enforcement that beats identity-provider revocation and a 'kill switch' at the network layer, while the cluster supplies no latency data, no deployment, and no independent test to support any of it. The urgency case rests on two percentages the reporting did not gather and cannot characterize. The gap is meaningful but not extreme: the underlying mechanism -- EDR risk signal into NAC policy enforcement -- is mundane and plausible, and the article itself flags the sourcing of the statistics rather than laundering them.
Vendor-announcement pipeline with visible commercial stakes
Every capability and framing claim originates with Portnox, a venture-backed company that has raised about $59.5 million and needs to differentiate against IAM and PAM incumbents in an agent-security land grab; the only two people quoted are its CEO and its field CISO. The publisher carries an explicit monetization and community-promotion appeal in the same page, and the demand-side statistics are borrowed from a third party rather than independently gathered, all of which points to a high-incentive, low-friction announcement channel.
Low: one publisher, one source, unverified key numbers
Confidence is limited by structure rather than by internal contradiction. The release facts, integration list, enforcement options and funding history are specific and unlikely to be wrong, so basic existence claims can be relied on. Anything about effectiveness, timing advantage, market prevalence or traction is single-sourced, vendor-voiced or borrowed, leaving the assessment's stronger conclusions provisional.
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
invest
Velatir's 5M euro seed prices AI oversight at about $12,500 a customer2 distinct publishers
security
Two years, 117 identified children: the only Com case this week with an outcome attached1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026