Product1 publisher3 min readPublished
Portnox adds Defender to its kill switch, conceding agent credentials outlive the login
The access control vendor now takes risk signals from Microsoft Defender, CrowdStrike and SentinelOne to cut an AI agent's connection mid-session. The pitch rests on numbers it did not gather.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Cloud-native access control company Portnox unveiled expanded capabilities aimed at governing AI agents and other nonhuman identities logging in to corporate networks, applications and infrastructure.
- The new piece of the announcement is an integration with Microsoft Corp.'s Defender.
- Portnox had already integrated CrowdStrike Holdings Inc. and SentinelOne Inc., and any of the three can now trigger an access decision.
- The mechanics run in three steps: one of the three endpoint platforms detects the risk, the Portnox policy engine weighs that signal against the customer's access rules in real time, and enforcement follows automatically.
- If one of the endpoint platforms reports a threat or sees a device slip out of compliance, the Portnox policy engine can cut the connection, drop the identity into quarantine or pull its access entirely, depending on what the customer's rules say.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Portnox has added an integration with Microsoft Defender to the access control product it sells for governing AI agents and other nonhuman identities logging in to corporate networks, applications and infrastructure [1][2]. CrowdStrike and SentinelOne were already wired in, and any of the three can now trigger an access decision [2][3].
The mechanics are described in three steps: one of the endpoint platforms detects risk, the Portnox policy engine weighs that signal against the customer's access rules in real time, and enforcement follows automatically [4]. If a threat is reported or a device slips out of compliance, the engine can cut the connection, drop the identity into quarantine, or pull its access entirely, depending on the rules the customer wrote [5]. Employees are subject to the same treatment [6].
The interesting part is what the product design admits. Agents authenticate to systems, pull sensitive data and act on their own, continuously and at machine speed [7], and yet many enterprises still issue them static credentials, shared accounts and standing permissions, then verify identity only once, at login [8]. A one-time check is not governance for something that keeps working after the check. Portnox calls its answer a kill switch at the network layer, and its argument is that identity and privileged access tools decide what an agent ought to reach, while severing the connection is a separate job that can be done before an identity provider has revoked anything [9][10]. That last claim is the company's, and the source material offers no independent latency measurement to support it.
Chief Executive Denny LeCompte said that "every identity that can connect, access data or act must be continuously verified and governed," and that Portnox lets organizations restrict access "when trust changes, without waiting for an AI agent to create a larger security incident" [11]. Field CISO Garrett Gross put the sales case more plainly: the recurring gap is "between knowing something's wrong and actually doing something about it," with plenty of products able to report strange agent behavior and far fewer able to act at the network layer without waiting on ticket approval [12].
The supporting numbers come from research by VentureBeat in the second quarter, cited by Portnox: 54% of enterprises reported a confirmed agent security incident, and 69% admitted to sharing credentials across their agents [13][14]. The credential-sharing figure runs 15 percentage points ahead of the incident figure [15], which is the more useful reading of the pair. The hygiene failure is already more widespread than the detected consequences, meaning the incident rate is a floor rather than a ceiling. Both figures are self-reported and neither was gathered by the vendor citing them.
Buyers should also note where enforcement starts. Because the chain begins with endpoint detection [4], coverage tracks wherever those three vendors have telemetry, which is a real constraint for agents running somewhere an endpoint sensor is not. The compensating deliverable is an audit trail covering which identity connected, when and from where, what it was cleared to reach, and which policy made the call [16].
Portnox has raised approximately $59.5 million, including a $37.5 million Series B led by Updata Partners in April 2025 [17], so roughly 63% of its total funding arrived in that single round [18]. Watch whether customers actually set these policies to revoke rather than alert, and whether rival network access vendors match the Defender hookup.