Listen to this Post

A Powerful Quarter Changes the Conversation
Okta has given investors something they have been waiting for: stronger financial results, improving profitability, rising cash generation, and a more optimistic outlook for the full fiscal year. The identity security company’s shares jumped more than 19% in extended trading after the company delivered second-quarter results that exceeded expectations.
The bigger story, however, goes beyond the stock market reaction. Okta is positioning itself for a rapidly changing security environment in which artificial intelligence agents are becoming capable of accessing corporate applications, moving information between systems and taking actions with limited human intervention.
That shift creates a new security problem. Companies have spent years building systems to determine which humans can access which resources. Now they increasingly need to answer a harder question: Which AI agents are allowed to act, what are they allowed to access, and how can those actions be monitored?
Okta believes identity will sit at the center of that problem.
Okta Shares Jump Above $160
Okta shares surged more than 19% in after-hours trading Wednesday, moving above $160 after the stock had closed the regular session at $134.42.
The sharp reaction reflects more than a single earnings beat. Investors appear to be responding to a combination of stronger financial performance and Okta’s expanding opportunity in AI-related identity security.
The company is attempting to turn the rapid adoption of AI agents into a new demand driver for its identity platform, potentially opening another major security category beyond traditional workforce and customer identity management.
Revenue Reaches $805 Million
For the fiscal second quarter ended July 31, Okta reported revenue of $805 million, representing an 11% increase from the same period a year earlier.
Subscription revenue, which represents the overwhelming majority of the company’s business, increased 12% to $793 million.
That distinction matters because recurring subscription revenue gives investors greater visibility into future performance. Okta’s growing subscription base also indicates that customers continue to rely heavily on its identity infrastructure rather than treating identity security as a one-time technology purchase.
Profitability Shows Significant Improvement
Okta’s bottom line delivered another important signal.
The company reported GAAP net income of $116 million, or 65 cents per diluted share, compared with $67 million, or 37 cents per share, during the same quarter a year earlier.
That represents a substantial improvement in profitability.
On an adjusted basis, Okta earned $1.05 per share, up from 91 cents in the year-ago period.
The improvement suggests that Okta is becoming more efficient while continuing to grow, an especially important combination for investors who have become increasingly demanding about software companies’ ability to translate revenue growth into sustainable profits.
Backlog Provides Visibility Into Future Revenue
Okta’s remaining performance obligations, or RPO, increased 17% to $4.86 billion.
Current remaining performance obligations, which represent revenue expected to be recognized over the next 12 months, climbed 14% to $2.59 billion.
These numbers provide an important look beyond the current quarter.
A growing backlog indicates that customers have committed to future spending under existing contracts. While RPO does not guarantee that every future dollar will immediately become recognized revenue, the expansion gives Okta a meaningful base from which to build its next several quarters.
Cash Flow Strengthens the Financial Picture
Okta also generated considerably more cash.
Operating cash flow increased to $234 million, compared with $167 million in the year-ago quarter.
Free cash flow climbed to $227 million, up from $162 million.
Meanwhile, GAAP operating income more than doubled to $107 million.
The combination of stronger revenue, expanding profitability and improving free cash flow is particularly significant because it demonstrates that Okta’s growth strategy is not solely dependent on increasing sales.
The company is showing that its business can generate increasing amounts of cash while it expands into new security markets.
AI Agents Create a New Identity Problem
The most strategically important part of the earnings report may not be a financial number at all.
It is AI agents.
Traditional enterprise software generally operates through identifiable users. A person logs in, receives permissions and performs an action.
AI agents complicate that model.
An agent can potentially connect to multiple enterprise applications, retrieve sensitive information, make decisions and execute tasks on behalf of a person or organization. If that agent has excessive permissions, the consequences of a compromised or misconfigured system can be severe.
Identity therefore becomes a control layer for AI.
Every AI Agent Needs an Identity
Okta CEO and co-founder Todd McKinnon argued that as AI agents transform technology, each agent needs a trusted identity and clearly defined controls governing what it can access and what it can do.
That idea is becoming increasingly important across enterprise security.
An AI agent should not simply inherit unrestricted access from the employee who created it. Organizations need mechanisms to establish an agent’s identity, authenticate it, authorize specific actions, monitor its behavior and revoke access when necessary.
The challenge is essentially a new version of an old cybersecurity problem: least privilege.
But this time, the entity receiving the privileges may not be a human being.
Okta Targets AI Agent Security
Okta has introduced products including Okta for AI Agents and Auth0 for AI Agents.
The goal is to help organizations discover AI agents, secure their connections, govern permissions and respond to suspicious behavior.
That could become an increasingly valuable capability as enterprises move from experimenting with AI assistants to deploying autonomous systems inside production environments.
The distinction is important.
An AI chatbot that answers questions presents one security profile. An AI agent that can create financial transactions, modify databases, access customer records or interact with cloud infrastructure presents an entirely different risk.
The Rise of Non-Human Identities
The identity security market is also expanding beyond traditional employees and customers.
Machines, applications, service accounts, APIs and AI agents increasingly require identities of their own.
This creates a huge identity-management challenge.
Organizations can no longer assume that identity security is primarily about protecting usernames and passwords. Modern identity environments increasingly involve thousands or millions of machine-to-machine relationships.
AI agents add another layer because their behavior can be dynamic.
An agent might legitimately access one application today and require access to another tomorrow. The security system must determine whether that new behavior is authorized or potentially malicious.
Okta Completes Permiso Security Acquisition
Okta is also strengthening its identity threat detection capabilities through its acquisition of Permiso Security.
The transaction, announced in July, has now closed.
Permiso provides a cloud-native platform designed to identify and mitigate threats involving human, non-human and agentic identities across multi-cloud environments.
That capability could become strategically important as organizations increasingly operate across AWS, Microsoft Azure, Google Cloud and other infrastructure environments.
Moving Beyond Authentication
The Permiso acquisition addresses an important weakness in traditional identity security.
Authentication answers a relatively simple question: Who are you?
But modern attacks often begin after authentication.
A legitimate credential can be stolen. A legitimate service account can be compromised. A legitimate AI agent can be manipulated. A valid identity can suddenly begin performing abnormal actions.
Identity threat detection therefore has to look beyond the login event.
It needs to understand behavior.
Runtime Detection Becomes Critical
Okta plans to combine
That combination could allow organizations to establish a more complete identity security lifecycle.
The process begins with establishing identity and permissions.
It continues with monitoring behavior.
When suspicious activity appears, security teams need the ability to investigate and respond.
This is where runtime detection becomes particularly valuable.
P0 Labs Joins
Permiso’s P0 Labs threat research team will also become part of Okta’s research operation.
That could strengthen
Threat research is increasingly important because attackers are adapting quickly to cloud infrastructure and AI-driven environments.
The traditional perimeter is disappearing, and identity has become one of the most attractive targets.
Okta Raises Its Fiscal 2027 Outlook
Following the stronger quarter, Okta raised its fiscal 2027 forecast.
The company now expects annual revenue between $3.216 billion and $3.226 billion, representing growth of approximately 10% to 11%.
The revised outlook gives investors another reason for optimism.
A raised forecast following a strong quarter can signal that management sees enough underlying demand to justify greater confidence in the remainder of the fiscal year.
Why Investors Reacted So Strongly
The
Revenue growth remained healthy.
Subscription revenue continued to expand.
Profitability improved dramatically.
Free cash flow increased.
Backlog expanded faster than reported revenue.
AI created a potentially significant new market opportunity.
And the company raised its full-year outlook.
Individually, none of these factors would necessarily explain a 19% move.
Together, they create a much stronger investment narrative.
The Bigger Enterprise Security Shift
The deeper story is that identity is becoming the control plane for modern computing.
Cloud services changed where applications operate.
Mobile computing changed how employees connect.
Zero-trust security changed how organizations think about access.
AI agents may now change who or what is actually performing the work.
That final shift could have enormous consequences for identity security providers.
AI Could Become a Major Growth Engine
Okta does not need every AI agent to become its customer for AI to have a meaningful effect on the business.
Instead, AI adoption can increase the complexity of enterprise identity environments.
More agents mean more identities.
More identities mean more permissions.
More permissions create more potential attack paths.
And more attack paths create demand for better identity security.
That gives Okta an opportunity to benefit from AI adoption even when it is not directly selling the AI itself.
The Risk Behind the Opportunity
There is also a major challenge.
AI security is becoming an increasingly crowded market.
Cybersecurity companies across identity, cloud security, endpoint protection, data security and application security are attempting to position their platforms around AI agents.
Okta therefore has to demonstrate that its AI identity products provide measurable security value rather than simply attaching the word “AI” to existing identity capabilities.
Enterprise buyers will ultimately demand evidence.
They will want to know whether these systems actually prevent unauthorized access, detect abnormal behavior and reduce the time required to respond to incidents.
Identity Security Is Becoming More Complex
The future enterprise could contain enormous numbers of identities.
Employees will have identities.
Customers will have identities.
Applications will have identities.
Cloud workloads will have identities.
APIs will have identities.
Autonomous agents will have identities.
Each identity could possess different permissions and relationships.
Managing that complexity manually is impossible at scale.
Automation will therefore become essential.
Why Least Privilege Matters More Than Ever
An AI agent with broad access can become a powerful attack vector.
If an attacker compromises an agent or manipulates its instructions, excessive permissions could allow the agent to perform actions far beyond what it originally needed.
A strong identity architecture should therefore restrict every agent to the smallest possible set of permissions.
Access should be temporary where possible.
Actions should be logged.
Sensitive operations should require additional controls.
And suspicious behavior should trigger rapid intervention.
What Okta Is Really Selling
At its core, Okta is selling trust.
The company wants enterprises to trust that the right person, machine or AI agent is accessing the right resource for the right reason at the right time.
That sounds simple.
In modern enterprise environments, it is anything but simple.
The complexity of identities is increasing at the same time that attackers are becoming more sophisticated.
What Undercode Say:
Identity Is Becoming the New Security Perimeter
The old cybersecurity perimeter was relatively easy to visualize.
There was an internal network and an external network.
Today, that distinction has largely disappeared.
Employees work remotely.
Applications run across multiple clouds.
Customers access digital services from everywhere.
Machines communicate continuously.
APIs connect independent platforms.
AI agents can now perform tasks without direct human interaction.
This makes identity one of the most important security boundaries.
The question is no longer simply whether a device is inside or outside the network.
The question is whether a specific identity should be allowed to perform a specific action.
AI Makes Identity Security More Urgent
AI agents introduce a new category of privileged actors.
They can potentially operate faster than humans.
They can interact with several systems simultaneously.
They can make decisions based on contextual information.
They can execute repetitive tasks without waiting for human approval.
That productivity creates security risk.
A compromised agent could potentially become an automated insider.
This makes agent identity a serious security requirement rather than a marketing feature.
The Authentication Problem Is Only the Beginning
Authentication confirms identity.
Authorization determines permission.
Monitoring determines whether behavior makes sense.
Response determines what happens when something goes wrong.
Organizations increasingly need all four.
Okta’s strategy is interesting because it is moving toward this broader identity security model.
The Permiso acquisition strengthens the detection and response side of that equation.
Behavioral Monitoring Could Become Critical
Imagine an AI agent that normally reads data from one CRM system.
Suddenly, it begins accessing payroll records.
The credentials may still be valid.
Authentication may still succeed.
Traditional access controls might not immediately identify the activity as malicious.
Behavioral detection could identify the anomaly.
That is where runtime identity monitoring becomes powerful.
Cloud Environments Increase the Challenge
Modern companies rarely operate inside a single infrastructure environment.
They use multiple cloud providers.
They operate SaaS applications.
They maintain internal systems.
They connect third-party services.
They expose APIs.
The number of identity relationships can grow rapidly.
Okta’s ability to connect identity management with cloud identity threat detection could therefore become strategically valuable.
AI Agents Will Need Permission Boundaries
Not every AI agent should have access to every application.
An agent performing customer-service tasks should not automatically have access to financial systems.
An engineering agent should not automatically receive access to production databases.
A marketing agent should not automatically gain access to confidential employee information.
Identity systems can establish these boundaries.
Temporary Access Could Become Standard
Long-lived credentials create unnecessary risk.
Future AI systems may increasingly rely on short-lived credentials and dynamically granted permissions.
An agent receives access when it needs it.
The access expires afterward.
That approach reduces the damage caused by credential theft.
Identity Threat Detection Could Become a Core SOC Function
Security operations centers traditionally focus heavily on endpoints, networks and logs.
Identity behavior deserves equal attention.
A suspicious login is important.
But suspicious activity after a legitimate login can be even more revealing.
The next generation of SOC platforms may therefore treat identity telemetry as a primary detection source.
Okta Has a Strategic Advantage
Okta already operates inside the identity layer of many enterprises.
That gives the company an important starting position.
It already understands users and access relationships.
The challenge is extending that visibility to machines and autonomous agents.
If Okta succeeds, it could transform its platform from an identity provider into a broader identity security control system.
But Competition Will Be Intense
The opportunity will not belong to Okta automatically.
Cloud providers are building their own identity controls.
Cybersecurity vendors are expanding into identity.
AI companies are developing agent-security mechanisms.
Enterprise software companies are implementing authorization frameworks.
Okta will need strong execution to maintain differentiation.
Financial Performance Gives Okta Breathing Room
The earnings results provide a financial foundation for that strategy.
Revenue is growing.
Profitability is improving.
Free cash flow is increasing.
Backlog is expanding.
The raised fiscal outlook gives management additional credibility.
That matters because major platform transitions require sustained investment.
The Real Test Is Adoption
The next question is not whether companies are interested in AI identity security.
They clearly are.
The important question is whether enterprises will pay for dedicated products at meaningful scale.
If AI agents become deeply embedded into business processes, identity controls could become mandatory infrastructure.
That would represent a much larger opportunity than a temporary AI spending cycle.
Undercode’s Bottom Line
Okta’s earnings demonstrate that the company is improving financially while pursuing a potentially important expansion of its identity security platform.
The AI opportunity is particularly interesting because autonomous agents are creating identity problems that traditional access-control systems were not designed to handle.
The Permiso acquisition strengthens the
That combination of identity, authorization, threat detection and AI-agent governance could become a powerful enterprise security architecture.
The biggest risk is execution.
Okta must prove that its AI-agent security products solve real problems and generate measurable customer value.
If it succeeds, the company could benefit from one of the most important changes taking place in enterprise computing.
AI may be changing who performs the work.
Okta wants to make sure organizations can still control exactly who, or what, is allowed to do it.
Deep Analysis: Testing
Check Current Identity Context
Security teams can begin by examining active identity sessions and authentication events:
who w last -a
These commands provide basic visibility into active and historical sessions on Linux systems.
Inspect Running Processes
Understanding which processes are currently executing can help identify unexpected activity:
ps aux --sort=-%cpu | head -20
Unexpected processes associated with service accounts deserve additional investigation.
Review Network Connections
Identity attacks frequently involve communication with external infrastructure.
ss -tulpn
Security teams can compare listening services and active connections against approved baselines.
Search Authentication Logs
Linux authentication events can provide valuable evidence:
sudo journalctl -u ssh --since "24 hours ago"
Organizations should investigate unusual authentication times, unexpected source addresses and repeated failures.
Audit Privileged Activity
Administrators can review privileged command execution where audit logging is enabled:
sudo ausearch -m USER_CMD --start today
This becomes particularly important when automated identities are granted administrative privileges.
Examine Cloud Identity Behavior
For cloud environments, security teams should correlate identity events with API activity.
A successful login should not automatically be considered safe.
Security monitoring should ask what happened immediately afterward.
Track Machine Identities
Organizations should maintain inventories of service accounts, API credentials, workloads and automated identities.
Unused identities should be disabled.
Excessive permissions should be removed.
Long-lived credentials should be replaced wherever practical.
Monitor AI Agent Permissions
AI agents should receive explicit permission scopes.
Security teams should document which applications each agent can access.
Every privileged action should be attributable to a specific identity.
Detect Behavioral Changes
A major security advantage comes from identifying when an identity behaves differently from its established baseline.
An account that normally reads data but suddenly deletes records should generate an alert.
The same principle applies to AI agents.
Apply Least Privilege
Permissions should be limited to the minimum required functions.
For Linux environments, administrators can inspect account privileges with:
sudo -l -U username
The same principle should be applied to cloud identities and AI agents.
Rotate Credentials
Long-lived credentials create unnecessary exposure.
Where supported, organizations should use short-lived credentials, automated rotation and centralized secret management.
Build an Identity-Centric Incident Response Plan
Security teams should know how to disable compromised identities quickly.
For an enterprise environment, this includes human users, service accounts, API credentials, workloads and AI agents.
The ability to revoke access immediately can dramatically reduce the impact of an identity compromise.
Financial Results
✅ Confirmed: Okta reported $805 million in second-quarter revenue, with subscription revenue reaching $793 million and GAAP net income reaching $116 million.
AI and Permiso Strategy
✅ Confirmed: Okta is expanding into AI-agent identity security and completed its acquisition of Permiso Security, strengthening its identity threat detection capabilities.
Fiscal Outlook
✅ Confirmed: Okta raised its fiscal 2027 revenue outlook to approximately $3.216 billion to $3.226 billion, representing roughly 10% to 11% growth.
Prediction
(+1) AI Identity Security Could Become a Major Enterprise Category
AI agents are likely to increase demand for identity, authorization and behavioral monitoring systems.
Organizations will increasingly need dedicated controls for non-human and autonomous identities.
Okta’s existing enterprise identity footprint could give it an advantage as companies expand into agentic workflows.
The combination of Okta’s identity platform and Permiso’s threat detection capabilities could strengthen the company’s competitive position.
(-1) Competition Could Limit the Upside
Cloud providers and cybersecurity companies are aggressively targeting AI security.
Enterprises may consolidate security spending into broader platforms rather than purchasing specialized AI-agent products.
Okta will need to demonstrate that its AI security products deliver measurable protection and are not simply extensions of existing identity capabilities.
(+1) The Long-Term Identity Market Looks Stronger
The number of digital identities is likely to keep expanding as machines and AI agents become active participants in enterprise workflows.
More identities mean more permissions, credentials and behavioral signals that organizations must secure.
Identity could increasingly become the central security layer connecting humans, machines, applications and autonomous agents.
The Bigger Picture
Okta’s latest results tell a story that goes beyond a one-day stock rally.
The company is improving its financial performance while repositioning identity security for an era in which software agents can act independently.
That transformation could make identity more important than ever.
The enterprise of the future will not be operated only by employees sitting behind computers. It will increasingly be operated by networks of humans, applications, machines and autonomous AI systems.
Every one of those actors will require boundaries.
Every permission will matter.
Every unusual action will need to be investigated.
And every organization will need to know exactly who or what is acting inside its digital environment.
That is the opportunity Okta is pursuing.
The company’s challenge now is proving that it can turn that opportunity into durable growth, stronger customer adoption and long-term leadership in the rapidly evolving identity security market.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.securityweek.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




