Portnox Adds a Network ‘Kill Switch’ to Cut Off Risky AI Agents

AI agents are starting to get permissions to reach enterprise applications, data, and infrastructure, but that autonomy brings a security problem: what happens when a compromised, misconfigured, or over-permitted agent keeps running at machine speed. Portnox has expanded its access control platform to automatically block, quarantine, or revoke the connectivity of these non-human identities when other security systems detect a change in risk.

AI agent control in 30 seconds

  • Portnox extends its continuous access policies to AI agents and other non-human identities.
  • A new integration with Microsoft Defender joins existing ones with CrowdStrike and SentinelOne.
  • If the risk level changes, the platform can automatically block, isolate, or revoke an agent’s access.
  • The decision is enforced at the network layer, regardless of the system that originally manages the identity.
  • The approach brings Zero Trust principles to agents that can work continuously and across many systems.

Portnox’s kill switch label is striking, but it’s worth being clear about what it does. There’s no big button that shuts down an AI or deactivates the underlying model. Instead, the platform gives you an independent point from which to cut its access to certain corporate resources.

That distinction matters. An agent can still exist or run, but it won’t have connectivity to systems where security policies no longer consider access appropriate.

This capability is getting more relevant as companies move from using AI only to answer questions toward systems that can take actions.

The new security concern: non-human identities

For decades, corporate identity policies were built mainly around people.

An employee provides credentials, uses multi-factor authentication, and gets permissions to reach certain applications. Later came devices, virtual machines, services, APIs, and other machine identities.

AI agents add a new twist.

An agent can authenticate across different services, query sensitive information, use tools, take actions, and move between systems without a human in the loop for each operation.

And it can do that around the clock, much faster than a person.

The problem shows up when organizations apply overly static access models to these agents. Shared credentials, common accounts, overly broad permissions, or authentication that only checks identity at session start can fall short if behavior changes later.

A valid credential doesn’t mean everything the agent does should count as legitimate.

You can have a legitimate identity whose behavior has changed because its credentials were compromised, an integration was misconfigured, or the agent is trying actions outside its intended scope.

That’s where Portnox wants to extend the Zero Trust model to AI identities: trust shouldn’t be granted permanently after the initial authentication.

Defender, CrowdStrike, and SentinelOne provide the signals

The expansion Portnox announced adds an integration with Microsoft Defender, on top of existing ones with CrowdStrike and SentinelOne.

These systems supply threat intelligence, device health status, and suspicious-behavior signals.

Portnox then uses those signals in its own policy engine.

The process has three steps.

First, one of the integrated systems detects a risk increase, threat, or posture change. Then Portnox evaluates that information against organizational policies. Finally, it can apply an automatic response.

That response can include blocking access, quarantining the connection, or revoking connectivity to specific resources.

What sets Portnox apart is that this decision can be enforced at the network layer, without waiting for the identity management system to change permissions.

That gives a second layer of containment.

An Identity and Access Management (IAM) system might set the initial permissions, but Portnox adds a layer that keeps checking whether those conditions still hold.

An agent can do in seconds what would take a person hours

Automating the response is also about speed.

Traditional enterprise security procedures might involve an alert, an analyst review, an incident, and a decision about the account or device.

That’s sensible in many cases, but it can be far too slow against an agent that can run hundreds or thousands of automated operations.

An agent with access to multiple tools could query databases, make API calls, change files, or interact with various applications while the security team is still looking at the first alert.

Hence the need for policies that can trigger automated responses when risk crosses organizational thresholds.

That doesn’t mean every unexpected behavior should automatically lead to disconnection. Policies can set different responses based on context and risk level.

An agent might lose access to a resource, be confined to a specific network zone, or be fully isolated.

Zero Trust will have to adapt to AI agents

The rise of enterprise agents also forces a rethink of a concept the industry has applied to employees and devices for years.

Zero Trust rests on the idea of not assuming permanent trust just because an identity is inside the corporate network or has passed authentication.

With agents, that philosophy takes on a different dimension.

Organizations will need to know which agent is connected, from where, what permissions it has, which resources it can reach, and what policies drove each decision.

Portnox says its platform logs this information to provide traceability and auditability.

It also aims to limit lateral movement. If an AI identity is compromised, cutting the number of systems it can reach helps contain how far the incident can spread.

That’s the same principle of least privilege long used in cybersecurity, now applied to software that can make decisions and act on its own.

Controlling agents will matter as much as deploying them

The current race around AI agents is about letting models do more: use browsers, write code, query databases, manage enterprise applications, or run whole workflows.

But each new capability usually needs a new permission.

The more tools an agent has, the bigger the surface organizations have to control. So the next big challenge may not just be how to deploy agents, but how to manage thousands of software identities with different credentials, privileges, and levels of autonomy.

Portnox’s approach anticipates that.

Security platforms will no longer only tell apart employees, devices, and services. They’ll have to add AI agents to the identity inventory and keep assessing how much to trust them.

The kill switch is one possible answer: when an identity no longer meets the trust conditions, the network can revoke its access before a human steps in.

This doesn’t solve every risk tied to AI agents. An agent might make legitimate mistakes from an identity or network view, and controls will also have to extend to permissions, applications, data, and tools.

But it marks an important shift. As agents behave more like autonomous users inside organizations, security systems have to start treating them that way.

Frequently Asked Questions

What is Portnox’s “kill switch” for AI agents?

It’s an access control feature that can block, quarantine, or revoke an AI identity’s connectivity when organizational policies decide its risk level has changed.

Can Portnox fully disable an AI model?

Not exactly. The feature acts as a policy enforcement point at the network layer and can cut the agent’s access to enterprise resources.

Which security platforms does it integrate with?

Portnox reports integrations with Microsoft Defender, CrowdStrike, and SentinelOne to feed risk signals into the decision process.

Why do AI agents need different controls?

Because they can act autonomously, continuously, and at machine speed across many systems. A credential valid at session start doesn’t guarantee that every later action stays authorized.

via: portnox

Scroll to Top