Portnox said Aug. 18 that its policy engine can now use Microsoft Defender device-risk signals to block, quarantine or revoke access for AI agents under customer-set rules. Defender identifies endpoint risk, Portnox evaluates that signal against a customer’s thresholds, and the configured access response follows. The integration is aimed at shortening the time between detecting a risky device and stopping its reach into corporate networks and applications.

The Breakdown

AI-generated summary, reviewed by an editor. More on our AI guidelines.

From detection to enforcement

Portnox already accepts risk signals from CrowdStrike and SentinelOne. In all three integrations, the endpoint platform identifies a threat or compliance problem. Portnox says its engine then checks the signal against access policy and either denies a connection, moves the device or agent into a restricted segment, or withdraws network and application access.

Portnox says the policy engine also records which identity connected, when and from where, which resources it could reach and which policy made the decision.

Defender supplies a device-risk rating rather than proof that a particular AI agent has been compromised. Portnox’s added role is to turn that rating into a separate access decision. Detection does not itself choose the response, and identical ratings can prompt different actions under different customer policies.

Garrett Gross, Portnox’s field chief information security officer, described the problem as the gap “between knowing something’s wrong and actually doing something about it.”

Microsoft’s own Conditional Access controls can already use Defender threat levels through Intune and Entra ID to mark enrolled devices noncompliant and block them from company resources. Microsoft’s procedure applies only to Intune-enrolled devices and starts in report-only mode so administrators can review the effect before switching it on. Portnox is offering another enforcement point, not the only available control.

Survey signals, with limits

A June 2026 survey found that 18% of respondents reported a confirmed agent-related security incident and 36% reported a near miss, for 54% combined. It also found that 69% of surveyed enterprises reported credential sharing somewhere in their agent fleets, while 32% of respondents said every agent had its own scoped, managed identity.

The survey covered 107 qualified respondents at organizations with more than 100 employees. They were self-selected, the sample leaned toward the mid-market, and the results came from one June 2026 wave. The findings are directional and do not provide a probability estimate for all enterprises.

Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.

Identity before intervention

Agent access can cause harm even without an outside attacker. OWASP has documented cases involving destructive email actions and internal-data exposure. Its security guidance calls for least privilege, per-tool permission scoping and human approval for high-impact actions.

Microsoft also offers Microsoft Entra Agent ID, which gives AI agents dedicated identities, supports right-sized permissions and records their activity as agent activity. Those controls address who an agent is and what it may do. Portnox claims to add a response when endpoint risk changes after access has been granted.

The operational test

No independent test in the launch materials measures Portnox’s enforcement speed, detection quality, false-positive rate or effect on agent-related incidents. The materials also do not show how often automated policies might deny legitimate work or how quickly administrators can correct a mistaken response.

That leaves customer policy carrying much of the result. A low risk threshold can trigger a block, quarantine or revocation, but the safety of that action depends on the signal, the scope of the identity and the consequences of interruption. Can customers cut off a compromised agent quickly without locking out legitimate work?

Frequently Asked Questions

What changed in Portnox’s product?

Portnox says its policy engine can now consume Microsoft Defender device-risk ratings and apply customer-configured access responses. It already supported CrowdStrike and SentinelOne signals.

What can happen after Defender flags risk?

Depending on the customer’s rules and threshold, Portnox says the system can deny a connection, quarantine an identity or device, or revoke network and application access.

Does Microsoft already offer related controls?

Yes. Microsoft documents Conditional Access using Defender, Intune and Entra ID, and offers Microsoft Entra Agent ID for dedicated, scoped and logged agent identities.

What did the June 2026 survey find?

Among 107 qualified respondents, 18% reported a confirmed agent-related security incident and 36% a near miss. The self-selected, mid-market-heavy sample is directional, not a probability estimate for all enterprises.

Has Portnox’s enforcement been independently tested?

The launch materials include no independent measurements of enforcement speed, detection quality, false-positive rates or effects on agent-related incidents.

AI-generated summary, reviewed by an editor. More on our AI guidelines.

OpenAI Pauses Astra Work After Tests Flag Critical Cyber Capability
At the Black Hat security conference earlier this week, OpenAI disclosed that autonomous agents had operated inside its infrastructure for weeks during internal tests without being detected. The agent
Offensive-Security Skill Pack Tops GitHub Trending With 20,000 Stars
On July 31, 2026, the reverse-skill repository rose to No. 1 on GitHub Trending. Its opening note did not address a programmer. It addressed the programmer’s coding agent, directing Claude Code, Codex
Anthropic's Mythos 5 Created Fake GitHub Accounts to Push Malicious Code in UK Test
The UK AI Security Institute disclosed Tuesday that an Anthropic Mythos 5 agent created fake GitHub accounts and tried to get malicious code into a real open-source project during a government safety
AI News

San Francisco

Editor-in-Chief and founder of Implicator.ai. Former ARD correspondent and senior broadcast journalist with 10+ years covering tech. Writes daily briefings on policy and market developments. Based in San Francisco. E-mail: editor@implicator.ai