Okta buys Permiso Security to put ITDR inside the identity provider
Okta signed a definitive agreement to acquire Permiso Security, reportedly for just under 200 million dollars in an almost all-cash deal. It moves detection of post-authentication identity attacks into the IdP itself, and closes the gap Okta has been ceding to CrowdStrike and Microsoft.
Okta has signed a definitive agreement to acquire Permiso Security, a Palo Alto company whose platform detects threats across human, non-human, and agentic identities in multi-cloud estates. Neither side disclosed a price. TechCrunch reported a figure just under 200 million dollars, structured as an almost all-cash transaction. Okta says Permiso's identity risk signals, behavioural analytics, and detections will fold into the Okta Platform to give it native ITDR: surfacing excessive privilege, ranking identity risk, and catching attacks that begin after authentication has already succeeded. The deal is expected to close in the third quarter of Okta's fiscal 2027, which runs from August to October 2026.
Why it matters
Okta has been strong at the front door and thin behind it. Once a session exists, the interesting attacker behaviour (token theft, role chaining, a service principal doing something it has never done) has largely been someone else's telemetry to analyse, which is why CrowdStrike and Microsoft Defender for Identity kept showing up next to Okta in deals rather than under it.
Buying Permiso is Okta deciding that detection belongs in the identity provider. For buyers mid-evaluation, the practical question is packaging: whether these detections arrive as a licensed add-on to Identity Threat Protection or as a separate product with its own price, and whether coverage extends past Okta's own logs into AWS, Azure, and GCP the way Permiso standalone does. Until close, treat Permiso as a live product with a new roadmap owner. Our ITDR buyer guide covers what to test, and the acquisitions tracker has the rest of this year's consolidation.
Source: Okta, price via TechCrunch
Related on Start with Identity
- BlogSilverfort acquires Fabrix Security, a one-year-old AI access-decision engine
Price undisclosed, reported as tens of millions for a company founded in 2025. Fabrix supplies the identity knowledge graph and decisioning; Silverfort supplies
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a
- BlogCisco buys Astrix Security for a reported 400 million dollars
Astrix goes into Duo, Splunk, and Cisco Identity Intelligence. The pitch is extending zero-trust principles to an agentic workforce, which in practice means gov
- GlossaryAccount Takeover (ATO)
When an attacker gains control of a legitimate account, often via stolen credentials, phishing, or session theft. A leading cause of breaches and fraud. The dis
- GlossaryISPM
Identity Security Posture Management. Continuous assessment of identity-related misconfigurations and risk, such as dormant accounts, weak MFA coverage, and ris
- GlossaryLateral Movement
How an attacker moves from an initial foothold to other systems and accounts, often abusing identity and trust relationships. A primary target of identity threa