Portnox creates a “switch” to isolate dangerous AI agents

Artificial intelligence agents are starting to receive permissions to access enterprise applications, data, and infrastructure, but this autonomy introduces a security problem: what happens when a compromised, misconfigured, or overly permitted agent continues operating at machine speed. Portnox has expanded its access control platform to automatically block, quarantine, or revoke the connectivity of these non-human identities when other security systems detect a risk change.

The keys to AI agent control in 30 seconds

  • Portnox extends its continuous access policies to AI agents and other non-human identities.
  • A new integration with Microsoft Defender joins existing ones with CrowdStrike and SentinelOne.
  • If the risk level changes, the platform can automatically block, isolate, or revoke an agent’s access.
  • The decision is applied at the network layer, regardless of the system originally managing the identity.
  • The approach brings Zero Trust principles to agents that can work continuously and across multiple systems.

The concept of a kill switch used by Portnox is striking, though it’s important to clarify what it actually does. There is no big button that simply shuts down an AI or deactivates the underlying model. Instead, the platform provides an independent point from which to cut off its access to certain corporate resources.

This distinction is important. An agent can still exist or run, but it will no longer have connectivity to systems where security policies no longer consider access appropriate.

This capability is becoming increasingly relevant as companies shift from using AI solely for answering questions to deploying systems capable of executing actions.

The new security concern: non-human identities

For decades, corporate identity policies have been primarily designed around people.

An employee provides credentials, uses multi-factor authentication, and gains permissions to access certain applications. Later came devices, virtual machines, services, APIs, and other machine identities.

AI agents introduce a new variation.

An agent can authenticate across different services, query sensitive information, use tools, perform actions, and move between multiple systems without human intervention for each operation.

Moreover, it can do so permanently and much faster than a human.

The problem arises when organizations apply overly static access models to these agents. Shared credentials, common accounts, excessively broad permissions, or authentication that only verifies identity at session start can be insufficient if behaviors change later on.

A valid credential doesn’t necessarily mean everything the agent does should be considered legitimate.

There might be a legitimate identity whose behavior has changed because its credentials were compromised, an integration was misconfigured, or the agent is attempting actions outside intended parameters.

This is where Portnox aims to extend the Zero Trust model to AI identities: trust should not be granted permanently after initial authentication.

Defender, CrowdStrike, and SentinelOne provide signals

The expansion announced by Portnox incorporates an integration with Microsoft Defender, in addition to existing ones with CrowdStrike and SentinelOne.

These systems provide threat intelligence, device health status, and suspicious behavior signals.

Portnox then uses these signals within its own policy engine.

The process has three steps.

First, a risk increase, threat, or posture change is detected by one of the integrated systems. Next, Portnox evaluates this information using organizational policies. Finally, it can apply an automatic response.

This response can include blocking access, quarantining the connection, or revoking connectivity to specific resources.

What sets Portnox apart is that this decision can be enforced at the network layer, without waiting for the identity management system to alter permissions.

This provides a second layer of containment.

An Identity and Access Management (IAM) system might determine initial permissions, but Portnox adds an additional layer that continuously verifies if those conditions still hold.

An agent can do in seconds what a person would take hours

Automation of response is also about speed.

Traditional enterprise security procedures might involve alerting, analyst review, incident creation, and decision-making about the account or device.

While sensible in many scenarios, this process can be too slow compared to an agent capable of executing hundreds or thousands of automated operations.

An agent with access to multiple tools could query databases, make API calls, modify files, or interact with various applications while security teams are still investigating the first alert.

Hence the need for policies that can trigger automated responses when risk exceeds organizational thresholds.

This does not mean that every unexpected behavior should automatically lead to disconnection. Policies can set different responses based on context and risk level.

An agent might lose access to a resource, be confined to a specific network zone, or be completely isolated.

Zero Trust will need to adapt to AI agents

The emergence of enterprise agents also requires rethinking a concept that industry has applied for years to employees and devices.

Zero Trust is based on the principle of not assuming permanent trust just because an identity is inside the corporate network or has passed authentication.

With agents, this philosophy takes on a different dimension.

Organizations will need to know which agent is connected, from where, what permissions it has, which resources it can access, and what policies governed each decision.

Portnox claims its platform logs this information to provide traceability and auditability.

It also aims to limit lateral movement. If an AI identity is compromised, reducing the number of systems it can access helps contain the incident’s potential scope.

This is the same principle of least privilege traditionally used in cybersecurity, now applied to software capable of making decisions and acting autonomously.

Controlling agents will be as important as deploying them

The current race around AI agents is focused on enabling models to do more: use browsers, code, query databases, manage enterprise applications, or run entire workflows.

But each new capability often requires a corresponding new permission.

The more tools an agent has, the larger the surface organizations need to control. Therefore, the next big challenge may not be just how to deploy agents, but how to manage thousands of software identities with different credentials, privileges, and autonomy levels.

Portnox’s approach anticipates this scenario.

Security platforms will no longer only distinguish between employees, devices, and services. They will need to incorporate AI agents into the identity inventory and continuously assess their trustworthiness.

The so-called kill switch is one of the potential solutions: when an identity no longer meets trust conditions, the network can revoke its access before a human intervenes.

This does not solve all risks associated with AI agents. An agent might make legitimate errors from an identity or network perspective, and controls will also need to extend to permissions, applications, data, and tools.

But it marks an important shift. As agents increasingly behave like autonomous users within organizations, security systems must start treating them accordingly.

FAQs

What is Portnox’s “kill switch” for AI agents?

It is an access control feature that allows blocking, quarantining, or revoking an AI identity’s connectivity when organizational policies determine its risk level has changed.

Can Portnox completely disable an AI model?

Not exactly. The feature acts as a policy enforcement point at the network layer and can cut off the agent’s access to enterprise resources.

Which security platforms does it integrate with?

Portnox reports integrations with Microsoft Defender, CrowdStrike, and SentinelOne to incorporate risk signals into the decision process.

Why do AI agents need different controls?

Because they can operate autonomously, continuously, and at machine speed, accessing multiple systems. A credential valid at session start does not guarantee all subsequent actions remain authorized.

via: portnox

Scroll to Top