On August 24, 2026, Okta announced the general availability of Agent SSO, shifting how enterprises manage their digital labor force. This update moves away from the legacy practice of treating AI agents as generic service accounts. Instead, Okta is now registering agents that support the Cross App Access (XAA) standard as first-class identities within its Universal Directory, providing them with the same governance and visibility as human employees.
The scale of the challenge is immense. Data from a January 2026 survey by the Cloud Security Alliance (CSA) highlights that non-human identities (NHI) already outnumber human employees by more than 90:1 in many organizations, with some reporting ratios as high as 144:1. Despite this, the infrastructure to manage them remains thin. According to the 2026 Infrastructure Identity Survey, 70% of organizations grant AI systems more access than they would give a human employee doing the same job. The consequences are stark: systems with least-privileged AI access show a 17% incident rate, compared to a staggering 76% for over-privileged systems. Furthermore, only 34% of organizations apply the same security controls to their digital labor force as they do to their human staff.
The operational gaps are equally concerning. Research indicates that 78% of organizations have no documented policy for creating or removing AI agent identities, and only 28% of organizations can trace AI agent actions back to a human sponsor. With 51% of organizations reporting no clear ownership for their AI and NHI populations, the current state of agent management is effectively a wild west that is becoming increasingly unsustainable.
The mechanism behind Agent SSO is designed to replace the risky practice of using stored credentials. Instead, the system issues short-lived, identity-governed tokens. By bundling this capability into core SSO plans at no additional cost, Okta is attempting to normalize agent identity as a baseline requirement for enterprise security. At the heart of this initiative is XAA, an open, vendor-neutral OAuth extension that has been formally incorporated as the official Enterprise-Managed Authorization extension for the Model Context Protocol (MCP). This standard-based approach provides a consistent security layer across diverse AI workflows, building on industry efforts like Anthropic Inference Hooks and Snowflake MCP gateways.
The ecosystem supporting XAA is expanding rapidly, with partners including Cloudflare, Stytch by Twilio, WorkOS, Scalekit, Slack, Aquera, Archestra.AI, Keycard, Keycloak, MintMCP, and Zuplo. Okta is also a featured identity provider for Anthropic’s Claude Enterprise beta program via XAA, with joint customers including HubSpot, Ramp, and Webflow. This momentum is bolstered by broader industry signals, such as the NIST AI Agent Standards Initiative launched in February 2026 and the CSA’s publication of the Agent Identity Governance Framework v1 in March 2026.
For IT and security teams, the competitive landscape remains split. Microsoft Entra Agent ID continues to be the primary choice for Microsoft-first organizations, leveraging deep integration within the Azure ecosystem. However, Okta is positioning itself as the preferred provider for multi-vendor and multi-cloud SaaS estates, where the complexity of managing disparate AI tools is highest. While Okta offers a separate subscription for non-XAA agents — which includes discovery of shadow AI, access certifications, and human owner assignment — the inclusion of XAA-based Agent SSO in the core product is a clear play to capture the standard-compliant segment of the market. As Ric Smith, President of Products and Technology at Okta, noted: “Okta is an undisputed leader in SSO, and now we’re bringing SSO for your AI agents. With Agent SSO, we are helping to establish a fundamental security standard for the agentic enterprise. By treating every connected agent as a first-class identity and bundling this capability directly into our core SSO offering, Okta is making it effortless for enterprises to secure AI workflows from day one.”
With Gartner projecting that 40% of enterprise applications will embed task-specific AI agents by the end of 2026, the stakes for human oversight are rising. Organizations that fail to apply the same rigor to their digital labor force as they do to their human employees face significantly higher incident rates. The focus will now be on how quickly the broader ecosystem adopts these identity standards to turn the tide on these risks.