[](https://www.paloaltonetworks.com/?ts=markdown) * [](https://www.paloaltonetworks.com/?ts=markdown) * Products Products AI Security [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-AIRS-logo-nav.svg)](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) [AI Security Platform](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Gateway](https://www.paloaltonetworks.com/ai-security/ai-gateway?ts=markdown) * [AI Model Security](https://www.paloaltonetworks.com/ai-security/ai-model-security?ts=markdown) * [AI Red Teaming](https://www.paloaltonetworks.com/ai-security/ai-red-teaming?ts=markdown) * [AI Runtime Security](https://www.paloaltonetworks.com/ai-security/ai-runtime-security?ts=markdown) * [Agent Security](https://www.paloaltonetworks.com/ai-security/agent-security?ts=markdown) * [AI Posture Management](https://www.paloaltonetworks.com/prisma/cloud/ai-spm?ts=markdown) Secure GenAI Tools * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) Network Security [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/strata-logo-nav.svg)](https://www.paloaltonetworks.com/network-security?ts=markdown) [Secure the Network](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [Next-Gen Trust Security](https://www.paloaltonetworks.com/network-security/next-gen-trust-security?ts=markdown) * [OT / Industrial Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [Device \& IoT Security](https://www.paloaltonetworks.com/network-security/device-security?ts=markdown) * [5G Security](https://www.paloaltonetworks.com/network-security/5g-security?ts=markdown) * [Managed Firewalls - Azure](https://www.paloaltonetworks.com/network-security/cloud-ngfw-for-azure?ts=markdown) * [Managed Firewalls - AWS](https://www.paloaltonetworks.com/network-security/cloud-ngfw?ts=markdown) [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Advanced IP Defense](https://www.paloaltonetworks.com/network-security/advanced-ip-defense?ts=markdown) SASE [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-sase-logo-nav.svg)](https://www.paloaltonetworks.com/sase?ts=markdown) [Secure Access (SASE)](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma Access (ZTNA)](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) Security Operations [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-logo-nav.svg)](https://www.paloaltonetworks.com/cortex?ts=markdown) [Security Operations](https://www.paloaltonetworks.com/cortex?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Extended Detection \& Response](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Security Orchestration \& Automation](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Attack Surface Management](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Exposure Management](https://www.paloaltonetworks.com/cortex/exposure-management?ts=markdown) * [Email Security](https://www.paloaltonetworks.com/cortex/advanced-email-security?ts=markdown) * [Threat Intelligence Management](https://www.paloaltonetworks.com/cortex/threat-intel-management?ts=markdown) * [Agentic-first Automation](https://www.paloaltonetworks.com/cortex/agentix?ts=markdown) * [Identity Threat Detection and Response](https://www.paloaltonetworks.com/cortex/itdr?ts=markdown) [Endpoint Security](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Endpoint Protection](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Agentic Endpoint Security](https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?ts=markdown) * [Ransomware Protection](https://www.paloaltonetworks.com/cortex/ransomware-protection?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/cortex/digital-forensics?ts=markdown) [Data Security](https://www.paloaltonetworks.com/cortex/data-security?ts=markdown) Cloud Security [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-cloud-logo-nav.svg)](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) [Application Security Overview](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Application Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/application-security-posture-management?ts=markdown) * [Software Supply Chain Security](https://www.paloaltonetworks.com/cortex/cloud/software-supply-chain-security?ts=markdown) * [Infrasture-as-Code (IaC) Security](https://www.paloaltonetworks.com/cortex/cloud/infrastructure-as-code-security?ts=markdown) * [Software Composition Analysis](https://www.paloaltonetworks.com/cortex/cloud/software-composition-analysis?ts=markdown) * [Secrets Security](https://www.paloaltonetworks.com/cortex/cloud/secrets-security?ts=markdown) * [Open Partner Ecosystem](https://www.paloaltonetworks.com/cortex/cloud/appsec-partner-ecosystem?ts=markdown) [Cloud Posture Security Overview](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/cloud-security-posture-management?ts=markdown) * [Cloud Infrastructure Entitlement Management](https://www.paloaltonetworks.com/cortex/cloud/cloud-infrastructure-entitlement-management?ts=markdown) * [Data Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/data-security-posture-management?ts=markdown) * [AI Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/ai-security-posture-management?ts=markdown) * [Vulnerability Management](https://www.paloaltonetworks.com/cortex/cloud/vulnerability-management?ts=markdown) * [Cloud Attack Surface Management](https://www.paloaltonetworks.com/cortex/cloud/attack-surface-management?ts=markdown) [Cloud Runtime Security Overview](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Cloud Detection and Response](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response?ts=markdown) * [Container \& Kubernetes Security](https://www.paloaltonetworks.com/cortex/cloud/kubernetes-and-container-security?ts=markdown) * [Cloud Workload Protection](https://www.paloaltonetworks.com/cortex/cloud/cloud-workload-protection?ts=markdown) * [API Security](https://www.paloaltonetworks.com/cortex/cloud/api-security?ts=markdown) * [Serverless Security](https://www.paloaltonetworks.com/cortex/cloud/serverless-security?ts=markdown) Identity Security [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/idira-logo-nav.svg)](https://www.paloaltonetworks.com/idira?ts=markdown) [Human Identities](https://www.paloaltonetworks.com/idira/human?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) [Machine Identities](https://www.paloaltonetworks.com/idira/machine?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) [See All Products](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [![Overview icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-default-orange.svg) Overview](#category-panel-0) * [![AI Security icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-prisma-blue.svg) AI Security](#category-panel-1) * [![Network Security icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-strata.svg) Network Security](#category-panel-2) * [![SASE icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-prisma-blue.svg) SASE](#category-panel-3) * [![Security Operations icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-cortex.svg) Security Operations](#category-panel-4) * [![Cloud Security icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-cortex.svg) Cloud Security](#category-panel-5) * [![Identity Security icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-idira.svg) Identity Security](#category-panel-6) [See All Products](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) [![AI Security icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-AIRS-logo-nav.svg) AI Security Discover, assess and protect AI apps, agents and employee use of GenAI tools](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) [![Network Security icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/strata-logo-nav.svg) Network Security AI-powered NetSec with next-gen firewalls, inline defense and unified management](https://www.paloaltonetworks.com/network-security?ts=markdown) [![Security Operations icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-logo-nav.svg) Security Operations Stop cyberattackers with the industry's premier platform for autonomous security operations](https://www.paloaltonetworks.com/cortex?ts=markdown) [![SASE icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-sase-logo-nav.svg) SASE Protect with AI, secure AI use and operate with AI using agentic Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) [![Identity Security icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/idira-logo-nav.svg) Identity Security Identity security platform to secure every identity: human, machine and agentic](https://www.paloaltonetworks.com/idira?ts=markdown) [![Cloud Security icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-cloud-logo-nav.svg) Cloud Security Prevent risks from code to cloud with the leading agentic cloud security platform](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) [![AI Security logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-AIRS-logo-nav.svg)](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) [AI Security Platform](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Gateway](https://www.paloaltonetworks.com/ai-security/ai-gateway?ts=markdown) * [AI Model Security](https://www.paloaltonetworks.com/ai-security/ai-model-security?ts=markdown) * [AI Red Teaming](https://www.paloaltonetworks.com/ai-security/ai-red-teaming?ts=markdown) * [AI Runtime Security](https://www.paloaltonetworks.com/ai-security/ai-runtime-security?ts=markdown) * [Agent Security](https://www.paloaltonetworks.com/ai-security/agent-security?ts=markdown) * [AI Posture Management](https://www.paloaltonetworks.com/prisma/cloud/ai-spm?ts=markdown) Secure GenAI Tools * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) [![Network Security logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/strata-logo-nav.svg)](https://www.paloaltonetworks.com/network-security?ts=markdown) [Secure the Network](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [Next-Gen Trust Security](https://www.paloaltonetworks.com/network-security/next-gen-trust-security?ts=markdown) * [OT / Industrial Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [Device \& IoT Security](https://www.paloaltonetworks.com/network-security/device-security?ts=markdown) * [5G Security](https://www.paloaltonetworks.com/network-security/5g-security?ts=markdown) * [Managed Firewalls - Azure](https://www.paloaltonetworks.com/network-security/cloud-ngfw-for-azure?ts=markdown) * [Managed Firewalls - AWS](https://www.paloaltonetworks.com/network-security/cloud-ngfw?ts=markdown) [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Advanced IP Defense](https://www.paloaltonetworks.com/network-security/advanced-ip-defense?ts=markdown) [![SASE logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-sase-logo-nav.svg)](https://www.paloaltonetworks.com/sase?ts=markdown) [Secure Access (SASE)](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma Access (ZTNA)](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) [![Security Operations logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-logo-nav.svg)](https://www.paloaltonetworks.com/cortex?ts=markdown) [Security Operations](https://www.paloaltonetworks.com/cortex?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Extended Detection \& Response](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Security Orchestration \& Automation](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Attack Surface Management](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Exposure Management](https://www.paloaltonetworks.com/cortex/exposure-management?ts=markdown) * [Email Security](https://www.paloaltonetworks.com/cortex/advanced-email-security?ts=markdown) * [Threat Intelligence Management](https://www.paloaltonetworks.com/cortex/threat-intel-management?ts=markdown) * [Agentic-first Automation](https://www.paloaltonetworks.com/cortex/agentix?ts=markdown) * [Identity Threat Detection and Response](https://www.paloaltonetworks.com/cortex/itdr?ts=markdown) [Endpoint Security](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Endpoint Protection](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Agentic Endpoint Security](https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?ts=markdown) * [Ransomware Protection](https://www.paloaltonetworks.com/cortex/ransomware-protection?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/cortex/digital-forensics?ts=markdown) [Data Security](https://www.paloaltonetworks.com/cortex/data-security?ts=markdown) [![Cloud Security logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-cloud-logo-nav.svg)](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) [Application Security Overview](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Application Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/application-security-posture-management?ts=markdown) * [Software Supply Chain Security](https://www.paloaltonetworks.com/cortex/cloud/software-supply-chain-security?ts=markdown) * [Infrasture-as-Code (IaC) Security](https://www.paloaltonetworks.com/cortex/cloud/infrastructure-as-code-security?ts=markdown) * [Software Composition Analysis](https://www.paloaltonetworks.com/cortex/cloud/software-composition-analysis?ts=markdown) * [Secrets Security](https://www.paloaltonetworks.com/cortex/cloud/secrets-security?ts=markdown) * [Open Partner Ecosystem](https://www.paloaltonetworks.com/cortex/cloud/appsec-partner-ecosystem?ts=markdown) [Cloud Posture Security Overview](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/cloud-security-posture-management?ts=markdown) * [Cloud Infrastructure Entitlement Management](https://www.paloaltonetworks.com/cortex/cloud/cloud-infrastructure-entitlement-management?ts=markdown) * [Data Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/data-security-posture-management?ts=markdown) * [AI Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/ai-security-posture-management?ts=markdown) * [Vulnerability Management](https://www.paloaltonetworks.com/cortex/cloud/vulnerability-management?ts=markdown) * [Cloud Attack Surface Management](https://www.paloaltonetworks.com/cortex/cloud/attack-surface-management?ts=markdown) [Cloud Runtime Security Overview](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Cloud Detection and Response](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response?ts=markdown) * [Container \& Kubernetes Security](https://www.paloaltonetworks.com/cortex/cloud/kubernetes-and-container-security?ts=markdown) * [Cloud Workload Protection](https://www.paloaltonetworks.com/cortex/cloud/cloud-workload-protection?ts=markdown) * [API Security](https://www.paloaltonetworks.com/cortex/cloud/api-security?ts=markdown) * [Serverless Security](https://www.paloaltonetworks.com/cortex/cloud/serverless-security?ts=markdown) [![Identity Security logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/idira-logo-nav.svg)](https://www.paloaltonetworks.com/idira?ts=markdown) [Human Identities](https://www.paloaltonetworks.com/idira/human?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) [Machine Identities](https://www.paloaltonetworks.com/idira/machine?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * Solutions Solutions By Use Case [![Drive AI Transformation icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/ai-page/teaser-block/teaser-icon-2.svg) Drive AI Transformation Scale enterprise AI adoption across employees, applications and agents with confidence and control](https://www.paloaltonetworks.com/ai-security?ts=markdown) [![Secure the Hybrid Network icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-strata.svg) Secure the Hybrid Network Stay ahead of AI-driven attacks with unified network security across hybrid environments](https://www.paloaltonetworks.com/network-security?ts=markdown) [![Accelerate Cloud Transformation icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-cortex.svg) Accelerate Cloud Transformation Build fast and innovate fearlessly with AI-driven protection from code to cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) [![Secure Every Identity icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-idira.svg) Secure Every Identity Stop identity-led breaches: Secure human, machine, and agentic identities with zero trust](https://www.paloaltonetworks.com/idira?ts=markdown) [![Enable Autonomous SOC icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-cortex.svg) Enable Autonomous SOC Fight AI with AI to stop threats at machine speed with the power of analytics and automation](https://www.paloaltonetworks.com/cortex/fight-ai-with-ai?ts=markdown) [![Achieve Cyber Resilience icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-Unit42.svg) Achieve Cyber Resilience Partner with world-class experts to proactively reduce risk, recover rapidly, and outsmart emerging threats](https://www.paloaltonetworks.com/unit42/ai-advantage?ts=markdown) * Services Services [![Threat Response icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/unit-logo-dark.svg) Threat Response Unit 42 combines threat intelligence, advanced technology and frontline expertise to help organizations prepare for attacks, respond faster and build lasting cyber resilience. Explore Unit 42Explore Unit 42](https://www.paloaltonetworks.com/unit42?ts=markdown) [Under Attack?](https://www.paloaltonetworks.com/unit42/contact-unit42?ts=markdown) Services Security Assessments * [Frontier AI Defense](https://www.paloaltonetworks.com/unit42/ai-advantage?ts=markdown) * [AI Security Assessment](https://www.paloaltonetworks.com/unit42/assess/ai-security-assessment?ts=markdown) * [Cloud Security Assessment](https://www.paloaltonetworks.com/unit42/assess/cloud-security-assessment?ts=markdown) * [BEC Readiness](https://www.paloaltonetworks.com/unit42/assess/business-email-compromise?ts=markdown) * [Ransomware Readiness](https://www.paloaltonetworks.com/unit42/assess/ransomware-readiness-assessment?ts=markdown) * [M\&A Cyber Due Diligence](https://www.paloaltonetworks.com/unit42/assess/mergers-acquisitions-cyber-due-diligence?ts=markdown) * [SOC Assessment](https://www.paloaltonetworks.com/unit42/assess/soc-assessment?ts=markdown) * [Supply Chain Risk](https://www.paloaltonetworks.com/unit42/assess/supply-chain-risk-assessment?ts=markdown) * [Unit 42 Retainer](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) Incident Response * [Incident Response](https://www.paloaltonetworks.com/unit42/respond/incident-response?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/unit42/respond/digital-forensics?ts=markdown) * [Unit 42 Retainer](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) General Risk * [Unit 42 Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown) * [Cyber Risk Assessment](https://www.paloaltonetworks.com/unit42/assess/cyber-risk-assessment?ts=markdown) * [Compromise Assessment](https://www.paloaltonetworks.com/unit42/assess/compromise-assessment?ts=markdown) * [Breach Readiness Review](https://www.paloaltonetworks.com/unit42/assess/breach-readiness-review?ts=markdown) Managed Services * [Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed Threat Hunting](https://www.paloaltonetworks.com/cortex/managed-threat-hunting?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Managed Firewalls - AWS](https://www.paloaltonetworks.com/network-security/cloud-ngfw?ts=markdown) * [Managed Firewalls - Azure](https://www.paloaltonetworks.com/network-security/cloud-ngfw-for-azure?ts=markdown) Adversarial Testing * [Pen Testing](https://www.paloaltonetworks.com/unit42/assess/penetration-testing?ts=markdown) * [Purple Team Exercises](https://www.paloaltonetworks.com/unit42/assess/purple-teaming?ts=markdown) * [Tabletop Exercises](https://www.paloaltonetworks.com/unit42/assess/tabletop-exercise?ts=markdown) * [Attack Surface Assessment](https://www.paloaltonetworks.com/unit42/assess/attack-surface-assessment?ts=markdown) Strategic Advisory * [Security Program Design](https://www.paloaltonetworks.com/unit42/transform/security-program-design?ts=markdown) * [IR Plan Development](https://www.paloaltonetworks.com/unit42/transform/incident-response-plan-development-review?ts=markdown) * [Virtual CISO](https://www.paloaltonetworks.com/unit42/transform/vciso?ts=markdown) * [Zero Trust Advisory](https://www.paloaltonetworks.com/unit42/transform/zero-trust-advisory?ts=markdown) [Global Customer Services](https://www.paloaltonetworks.com/services?ts=markdown) * [Education \& Training](https://www.paloaltonetworks.com/services/education?ts=markdown) * [Professional Services](https://www.paloaltonetworks.com/services/consulting?ts=markdown) * [Success Tools](https://www.paloaltonetworks.com/services/customer-success-tools?ts=markdown) * [Support Services](https://www.paloaltonetworks.com/services/solution-assurance?ts=markdown) * [Customer Success](https://www.paloaltonetworks.com/services/customer-success?ts=markdown) * Industries Industries [![Financial Services icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/financial-icon-2.svg) Financial Services Secure with AI cybersecurity, fraud and ransomware prevention, compliance, and customer data protection](https://www.paloaltonetworks.com/industry/financial-services?ts=markdown) [![Manufacturing icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/manufacturing-icon-2.svg) Manufacturing Secure with OT security, ransomware defense, industrial cybersecurity, supply chain resilience, and continuity](https://www.paloaltonetworks.com/industry/manufacturing?ts=markdown) [![Retail and Hospitality icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/retail-icon-2.svg) Retail and Hospitality Secure with payment security, PCI compliance, ransomware and fraud prevention, and data protection](https://www.paloaltonetworks.com/industry/retail?ts=markdown) [![Healthcare and Life Sciences icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/healthcare-icon-2.svg) Healthcare and Life Sciences Secure patient and clinical data, medical device security, ransomware defense, and HIPAA compliance](https://www.paloaltonetworks.com/industry/healthcare?ts=markdown) [![Public Sector icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/public-sector-icon-2.svg) Public Sector Secure with Zero Trust, cyber defense, compliance, infrastructure protection, and citizen data security](https://www.paloaltonetworks.com/industry/public-sector?ts=markdown) [![Utilities icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/utilities-icon-2.svg) Utilities Secure with power grid protection, OT network security, ransomware defense, and critical infrastructure security](https://www.paloaltonetworks.com/industry/electric-utilities?ts=markdown) [![Transportation icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/transportation-icon-2.svg) Transportation Secure OT and connected infrastructure protection, ransomware defense, supply chain security, compliance](https://www.paloaltonetworks.com/industry/transportation-security?ts=markdown) [![Small and Medium Business icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/smb-icon-2.svg) Small and Medium Business Secure against cyber threats using AI-powered endpoint, network, browser, cloud, and MDR](https://www.paloaltonetworks.com/industry/small-medium-business-portfolio?ts=markdown) * Partners Partners NextWave * [Partner Program](https://www.paloaltonetworks.com/partners/nextwave-partner-portal?ts=markdown) * [Become a Partner](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerregistration?type=becomepartner) * [Request Partner Portal Access](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerregistration?type=requestaccess) * [Partner Portal Login](https://www.paloaltonetworks.com/partners/nextwave-partner-portal?ts=markdown) * [Find a Partner](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerlocator) Partner Ecosystem [Explore All Partners Find the right partner network tailored to your business needs, cloud environments, and security requirements](https://www.paloaltonetworks.com/partners?ts=markdown) [Cloud Service Partners Bring cloud native security and compliance to the entire development lifecycle](https://www.paloaltonetworks.com/partners/nextwave-for-csp?ts=markdown) [Frontier AI Alliance Outpace today's cyberattacks through a global ecosystem of leaders orchestrating unified defenses](https://www.paloaltonetworks.com/frontier?ts=markdown) [Global System Integrators Speed and secure digital transformation with the industry's best technology, people and intelligence](https://www.paloaltonetworks.com/partners/nextwave-for-gsi?ts=markdown) [Managed Security Service Providers Gain valuable resource oversight to help your businesses administer security strategies](https://www.paloaltonetworks.com/partners/managed-security-service-providers?ts=markdown) [Resellers Deliver the most comprehensive cybersecurity portfolio while expanding opportunities and profitability](https://www.paloaltonetworks.com/partners/resellers?ts=markdown) [Service Providers Protect mobile users, devices and applications with effective, flexible and easy to deploy cybersecurity](https://www.paloaltonetworks.com/partners/service-providers?ts=markdown) [Technology Partners Advance security and transformation with innovative technology partner integrations](https://www.paloaltonetworks.com/partners/technology-partners?ts=markdown) * Resources Resources ![Learn icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/resource-library-icon.svg) Learn * [Resource Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Analyst Reports](https://www.paloaltonetworks.com/resources/research?ts=markdown) * [Customer Stories](https://www.paloaltonetworks.com/customers?ts=markdown) * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Threat Vector Podcast](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [Unit 42 Threat Research](https://unit42.paloaltonetworks.com/) * [Knowledgebase](https://knowledgebase.paloaltonetworks.com/) * [Technical Documentation](https://docs.paloaltonetworks.com/) ![Engage icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/engage-icon-2.svg) Engage * [Webinars](https://www.paloaltonetworks.com/resources/webinars?ts=markdown) * [Demos](https://www.paloaltonetworks.com/demos?ts=markdown) * [Test Drive](https://www.paloaltonetworks.com/resources/test-drives?ts=markdown) ![Connect icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/connect-icon-2.svg) Connect * [Executive Briefings](https://www.paloaltonetworks.com/about-us/executive-briefing-program?ts=markdown) * [Events](https://events.paloaltonetworks.com/) * [Live Community](https://live.paloaltonetworks.com/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) ![Discover icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/discover-icon-2.svg) Discover * [Why Palo Alto Networks?](https://www.paloaltonetworks.com/why-paloaltonetworks?ts=markdown) * [Platform Approach](https://www.paloaltonetworks.com/why-paloaltonetworks/platformization?ts=markdown) * [Awards \& Recognition](https://www.paloaltonetworks.com/about-us/awards?ts=markdown) * [Global Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown) * [Cloud Locations](https://www.paloaltonetworks.com/products/regional-cloud-locations?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Trust 360 Program](https://www.paloaltonetworks.com/resources/whitepapers/trust-360?ts=markdown) ![Company icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-default-orange.svg) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Management Team](https://www.paloaltonetworks.com/about-us/management?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en) * [Culture \& Benefits](https://jobs.paloaltonetworks.com/en/culture/) * [Ethics \& Compliance](https://www.paloaltonetworks.com/company/ethics-and-compliance?ts=markdown) * [Office Locations](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * ![search magnifying glass](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/search-black.svg) * EN Language * USA (ENGLISH) * [AUSTRALIA (ENGLISH)](https://www.paloaltonetworks.com.au) * [BRAZIL (PORTUGUÉS)](https://www.paloaltonetworks.com.br) * [CANADA (ENGLISH)](https://www.paloaltonetworks.ca) * [CHINA (简体中文)](https://www.paloaltonetworks.cn) * [FRANCE (FRANÇAIS)](https://www.paloaltonetworks.fr) * [GERMANY (DEUTSCH)](https://www.paloaltonetworks.de) * [INDIA (ENGLISH)](https://www.paloaltonetworks.in) * [ITALY (ITALIANO)](https://www.paloaltonetworks.it) * [JAPAN (日本語)](https://www.paloaltonetworks.jp) * [KOREA (한국어)](https://www.paloaltonetworks.co.kr) * [LATIN AMERICA (ESPAÑOL)](https://www.paloaltonetworks.lat) * [MEXICO (ESPAÑOL)](https://www.paloaltonetworks.com.mx) * [SINGAPORE (ENGLISH)](https://www.paloaltonetworks.sg) * [SPAIN (ESPAÑOL)](https://www.paloaltonetworks.es) * [TAIWAN (繁體中文)](https://www.paloaltonetworks.tw) * [UK (ENGLISH)](https://www.paloaltonetworks.co.uk) * Accounts \& Support Accounts \& Support * Accounts * Customer * Partner * Employee * [Login to Download](https://www.paloaltonetworks.com/login?ts=markdown) * [Become a Member](https://www.paloaltonetworks.com/login?screenToRender=traditionalRegistration&ts=markdown) * Support * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [What's New](https://www.paloaltonetworks.com/resources?ts=markdown) * [Get Support](https://support.paloaltonetworks.com/SupportAccount/MyAccount) [Under Attack?](https://www.paloaltonetworks.com/unit42/contact-unit42?ts=markdown) * [Demos and Trials](https://www.paloaltonetworks.com/get-started?ts=markdown) [Discover how prevention starts before the attack at InterSECt 2026. Watch Now](https://www.paloaltonetworks.com/intersect?ts=markdown) [Prisma AIRS AI Gateway is now generally available](https://www.paloaltonetworks.com/ai-security/ai-gateway?ts=markdown) [](https://www.paloaltonetworks.com/?ts=markdown) Search All * [Tech Docs](https://docs.paloaltonetworks.com/search) Close search modal 1. [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) 2. [AI Security](https://www.paloaltonetworks.com/cyberpedia/ai-security?ts=markdown) 3. [What Is Agent Identity?](https://www.paloaltonetworks.com/cyberpedia/what-is-agent-identity?ts=markdown) Table of contents * [Why Agent Identity Matters](#why) * [The Confused Deputy Problem at Enterprise Scale](#the) * [Why Traditional IAM Falls Short](#short) * [How Agent Identity Works](#work) * [Security Risks of Weak Agent Identity](#weak-agent) * [Best Practices for Agent Identity](#best) * [Replace Static Secrets with Verifiable Workload Identity](#replace) * [Agent Identity FAQs](#faqs) # What Is Agent Identity? 4 min. read [Explore PRISMA AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) [Book a Demo](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security#demo?ts=markdown) Table of contents * [Why Agent Identity Matters](#why) * [The Confused Deputy Problem at Enterprise Scale](#the) * [Why Traditional IAM Falls Short](#short) * [How Agent Identity Works](#work) * [Security Risks of Weak Agent Identity](#weak-agent) * [Best Practices for Agent Identity](#best) * [Replace Static Secrets with Verifiable Workload Identity](#replace) * [Agent Identity FAQs](#faqs) 1. Why Agent Identity Matters * [1. Why Agent Identity Matters](#why) * [2. The Confused Deputy Problem at Enterprise Scale](#the) * [3. Why Traditional IAM Falls Short](#short) * [4. How Agent Identity Works](#work) * [5. Security Risks of Weak Agent Identity](#weak-agent) * [6. Best Practices for Agent Identity](#best) * [7. Replace Static Secrets with Verifiable Workload Identity](#replace) * [8. Agent Identity FAQs](#faqs) Agent identity is a security construct that assigns each autonomous AI agent a distinct, verifiable credential tied to its purpose, owner, and authorized scope of action. Unlike human identity systems built around usernames and passwords, agent identity governs non-human actors that authenticate programmatically, execute tasks at machine speed, and operate across trust boundaries without interactive oversight. The core function is to attribute every tool call, data access, and inter-agent interaction to a specific agent, enforce least-privilege access, and provide the foundation for runtime governance of [agentic AI](https://www.paloaltonetworks.com/cyberpedia/what-is-agentic-ai-security?ts=markdown) systems. Key Points * **Non-Human Identity Gap:** Legacy IAM cannot govern autonomous agents or cross-system tool calls. \* **Credential Exposure:** Shared accounts prevent agent-level attribution and targeted isolation. \* **Privilege Amplification:** Agents may inherit excessive access, increasing the impact of compromise. \* **Runtime Accountability:** Unique identities enable monitoring, revocation, and auditable actions. \* **Delegation:** Agents need explicit, limited authority, not full user credentials. ## Why Agent Identity Matters Enterprise AI deployments have moved from conversational interfaces to autonomous agents that plan multi-step workflows, invoke external tools via protocols like [MCP](https://www.paloaltonetworks.com/cyberpedia/mcp-enterprise-adoption-challenges?ts=markdown), and collaborate with other agents. This shift transforms AI from a system that generates outputs into one that takes actions, and the identity layer has not kept pace. ## The Confused Deputy Problem at Enterprise Scale Most organizations still treat AI agents as extensions of human users, assigning them to shared service accounts or existing user credentials. When an agent inherits a human's full credential set, it becomes what security researchers call a "confused deputy": a legitimate actor with valid credentials whose autonomous decisions can exceed the intent of the person who authorized it. ## Why Traditional IAM Falls Short Human IAM systems assume interactive authentication, predictable access patterns, and a single point of accountability. AI agents violate all three assumptions. They authenticate programmatically, execute instructions at machine speed, operate across trust boundaries that span organizational perimeters, and can spawn child agents dynamically. | Traditional IAM Assumption | Agent Reality | | Interactive authentication (passwords, MFA) | Programmatic authentication at machine speed | | Predictable, role-based access patterns | Dynamic tool selection based on reasoning | | Single user per session | Multi-agent delegation chains and child agents | | Human judgment as a control | Autonomous execution without human review | | Long-lived credentials tied to a person | Credentials that should expire with each task | | Revocation through HR/IT workflows | Real-time revocation needed within seconds | |---------------------------------------------|------------------------------------------------| ## How Agent Identity Works Agent identity is a lifecycle, not a one-time authentication check. It spans four stages that organizations implement to varying degrees depending on maturity and risk tolerance. **Registration and Inventory** : Each agent is recorded in a centralized registry with a declared purpose, owner, risk tier, and set of authorized tools. Without a registry, security teams cannot distinguish approved agents from [shadow AI](https://www.paloaltonetworks.com/cyberpedia/what-is-an-ai-gateway?ts=markdown) operating outside governance. **Scoped Credential Issuance:** Rather than granting standing privileges, the identity system issues short-lived, task-scoped credentials when the agent needs them. Credentials expire automatically when the task completes. *Further reading: [What Is Workload Identity?](https://www.paloaltonetworks.com/cyberpedia/what-is-workload-identity?ts=markdown)* **Delegation Chain Tracking**: When a human delegates to an agent, or one agent delegates to another, the identity system records the full chain of authority: who authorized what, under which constraints, and for how long. Each link is independently verifiable, preventing one agent's credentials from propagating silently to another. **Runtime Enforcement and Revocation** : An [AI gateway](https://www.paloaltonetworks.com/cyberpedia/what-is-an-ai-gateway?ts=markdown) evaluates every request against the agent's identity, the specific task, and the sensitivity of the resource. Actions that exceed scope are blocked before execution. If an agent exhibits anomalous behavior, its identity and privileges are revoked instantly. ## Security Risks of Weak Agent Identity When agent identity is absent or poorly implemented, organizations expose themselves to a category of threats that traditional perimeter and endpoint security cannot address. These threats exploit the gap between authentication (verifying who an agent is) and runtime trust (verifying what it is doing). ### Credential Theft and Identity Spoofing [Unit 42 research into agentic AI threats](https://unit42.paloaltonetworks.com/agentic-ai-threats/) documented nine concrete attack scenarios targeting agentic applications, including credential leakage from improperly mounted container volumes, identity spoofing through weak authentication, and tool exploitation that chains compromised credentials into privilege escalation. Attackers who steal agent credentials gain an autonomous "insider" capable of lateral movement and data exfiltration without further external commands. ### Privilege Escalation Through Inherited Credentials Agents that silently inherit a human user's full credential set create a privilege amplification risk. An agent granted broad OAuth scopes to "be helpful" becomes a high-value target: a single prompt injection can redirect the agent to access resources far beyond the original task's intent. Without scoped, ephemeral credentials, there is no mechanism to contain the blast radius. ### Unauditable Delegation Chains In multi-agent workflows, one agent can create and instruct another. Without identity controls that track the delegation chain, the resulting actions become impossible to attribute. A security team investigating an incident sees a series of tool calls but cannot determine which agent initiated the sequence, which human authorized it, or where the chain was compromised. ### Shadow Agent Proliferation Teams deploy agents through SaaS tools, browser extensions, IDE plugins, and internal prototypes. Without a centralized registry that ties each agent to a verified identity, security teams have no inventory of what is operating in the environment. Unregistered agents represent the same risk as any unmanaged endpoint: an unknown entity with unknown permissions acting on unknown instructions. | Threat | Root Cause | Impact Without Agent Identity | | Credential theft | Static or shared secrets | Attacker gains persistent, broad access | | Identity spoofing | Weak or absent authentication | Malicious agent operates as a trusted entity | | Privilege escalation | Inherited human credentials | Single compromise extends across all user permissions | | Unauditable delegation | No chain-of-authority tracking | Incident attribution is impossible | | Shadow agent proliferation | No centralized registry | Unknown agents operate outside governance | |----------------------------|--------------------------------|-------------------------------------------------------| ### Agent Identity vs. Traditional Service Account Identity Agent identity is frequently confused with existing approaches to service account and machine identity management. The distinction matters because applying service account controls to AI agents leaves critical gaps. Service accounts are deterministic, and they execute predefined operations in a predictable sequence with fixed credential scopes. An AI agent, by contrast, reasons about its next action, selects tools dynamically, and may spawn sub-agents or chain calls across systems that were not anticipated at provisioning time. A service account that reads from one database on a schedule is a fundamentally different security principle than an agent that interprets a goal, decides which APIs to call, retrieves credentials at runtime, and adapts its behavior based on new context. | Dimension | Traditional Service Account | Agent Identity | | Behavior | Deterministic, predefined operations | Probabilistic, goal-driven reasoning | | Tool access | Fixed at provisioning | Dynamic, selected at runtime | | Credential lifetime | Long-lived, often manually rotated | Ephemeral, task-scoped, auto-expired | | Delegation | None (single-purpose) | Multi-level (human to agent, agent to agent) | | Monitoring | Periodic audit logs | Continuous behavioral analysis | | Revocation speed | Manual process (hours to days) | Automated, sub-second | | Accountability | Tied to a team or system | Tied to a specific agent, task, and human sponsor | |---------------------|--------------------------------------|---------------------------------------------------| ## Best Practices for Agent Identity Implementing agent identity requires changes to how organizations provision, govern, and monitor non-human actors across the AI stack. ### Every Agent as a First-Class Security Principal Assign each agent a unique identity at deployment, not a shared service account. The identity should include a declared purpose, an owner, a risk tier, and an expiration date. ## Replace Static Secrets with Verifiable Workload Identity Move from API keys and personal access tokens stored in environment files to standards-based [workload identity](https://www.paloaltonetworks.com/cyberpedia/what-is-workload-identity?ts=markdown). Provide each agent with a short-lived, verifiable identity tied to its runtime context. When a credential expires, the system issues a new one automatically, eliminating the window of exposure that static secrets create. ### Enforce Just-in-Time, Least-Privilege Access Standing privileges should be the exception, not the default. Issue credentials scoped to the specific task and tool the agent needs, for only as long as the task takes. Just-in-time access prevents privilege drift and reduces the blast radius of a compromised agent to a single task window. ### Deploy a Centralized Gateway as the Enforcement Point Route all agent traffic, including model calls, [MCP](https://www.paloaltonetworks.com/cyberpedia/mcp-enterprise-adoption-challenges?ts=markdown) tool invocations, and agent-to-agent communications, through a centralized gateway that verifies identity and enforces policy before execution. Without a central enforcement point, identity controls fragment across individual agent frameworks and become impossible to audit consistently. ### Log the Full Delegation Chain Every action an agent takes should be traceable to a human sponsor through a complete delegation chain. The audit trail should preserve the user identity, agent identity, model version, tool calls, policy decisions, and downstream changes. ### Inventory and Review Continuously Agent identity is not a deploy-and-forget control. Run continuous discovery to detect new agents, review permissions for drift, and decommission agents whose business justification has expired. The agentic AI governance lifecycle should include regular attestation reviews tied to the agent's risk tier. The gap between authentication and runtime trust is where agent identity failures become security incidents. Organizations scaling autonomous AI need to treat agent identity as foundational infrastructure, not an afterthought layered onto existing IAM. That means discovering every agent in the environment, assigning governed identities with scoped permissions, enforcing access policy at runtime through a centralized gateway, and maintaining audit trails that trace every action back to a specific agent and its human sponsor. The enterprises that build this identity layer now will be positioned to scale agentic AI with confidence. Those that defer it will inherit an expanding attack surface that moves at machine speed. ## Agent Identity FAQs ### What is agent identity in AI security? Agent identity is a security construct that assigns each AI agent a unique, verifiable credential tied to its purpose, owner, and authorized scope. It enables enterprises to attribute every action an agent takes to a specific entity, enforce least-privilege access, and revoke permissions instantly if the agent behaves anomalously. ### How is agent identity different from a service account? Service accounts are deterministic and execute predefined operations with fixed credentials. AI agents reason about tasks, select tools dynamically, and may spawn sub-agents. Agent identity accounts for this by issuing ephemeral, task-scoped credentials and maintaining full delegation chains that trace every action back to a human sponsor. ### Why can't organizations use existing IAM for AI agents? Traditional IAM assumes interactive authentication, predictable access patterns, and human judgment as a control. AI agents authenticate programmatically, operate at machine speed, cross trust boundaries, and spawn child agents dynamically. These differences require purpose-built identity controls including just-in-time access, runtime policy enforcement, and automated revocation. ### What happens if an agent's identity is compromised? With proper agent identity controls, the blast radius is limited to the agent's current task scope. Ephemeral credentials expire automatically, the identity system can revoke the agent's privileges within seconds, and the full audit trail allows security teams to trace exactly what the compromised agent accessed and which actions it took. Related content [What Is a Non-Human Identity (NHI)? Understand machine identities, including agent identities, service accounts, API keys, and workload credentials](https://www.paloaltonetworks.com/cyberpedia/what-is-a-non-human-identity?ts=markdown) [A Complete Guide to Agentic AI Governance Learn how to build governance frameworks that manage delegated authority, identity, and runtime controls.](https://www.paloaltonetworks.com/cyberpedia/what-is-agentic-ai-governance?ts=markdown) [Securing and Governing AI Agents at Scale Through a Unified AI Gateway See how Prisma AIRS and the AI gateway provide a unified control plane for enterprise agents.](https://www.paloaltonetworks.com/blog/ai-security/securing-and-governing-ai-agents-at-scale-through-a-unified-ai-gateway/?ts=markdown) [Prisma AIRS: Secure the Enterprise AI Lifecycle Get visibility, assurance, and runtime governance to deploy autonomous agents safely.](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) ![Share page on facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/facebook-circular-icon.svg) ![Share page on linkedin](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/linkedin-circular-icon.svg) [![Share page by an email](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/email-circular-icon.svg)](mailto:?subject=What%20Is%20Agent%20Identity%3F&body=Agent%20identity%20assigns%20each%20AI%20agent%20a%20unique%2C%20verifiable%20credential%20that%20governs%20what%20it%20can%20access%20and%20do.%20Learn%20how%20it%20works%20and%20why%20enterprises%20need%20it%20at%20https%3A//www.paloaltonetworks.com/cyberpedia/what-is-agent-identity) Back to Top {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language