Okta、Permisoを買収し、アイデンティティセキュリティをSOCに導入することで合意
Permisoの背後にいるFireEyeのベテランたちが、Oktaに対して人間、マシン、AIエージェントのアイデンティティにわたるランタイム検出を提供する。
By Ryan Merket · Published
Why it matters
Permiso gives Okta post-login threat detection, extending its reach from access management into security operations as AI agents and machine accounts multiply.

Okta said on July 30th that it signed a definitive agreement to acquire Permiso Security, the cloud identity threat-detection provider founded by former FireEye executives Paul Nguyen and Jason Martin. Financial terms were not disclosed.
この取引により、Oktaは認証後に人間ユーザー、サービスアカウント、AIエージェントが行う動作を検出する技術を獲得します。これにより、Oktaはセキュリティオペレーションの領域へとより深く進出し、チームはクラウドサービス全体での侵害された資格情報、過剰な権限、疑わしい行動を調査することになります。
Nguyen and Martin built Permiso around experience acquired during an earlier change in enterprise security. Nguyen began as a white-hat hacker at @stake and Neohapsis before founding security-orchestration provider Invotas, which FireEye acquired. Martin co-founded Secure DNA before becoming executive vice president of global engineering and security products at FireEye and Mandiant.
Permisoの創業メンバーには、Merakiでの経験を持つエンジニアリング兼プロダクト責任者のStephen Demjanenkoや、元FireEyeのエンジニアリングリーダーであるPhani Modaliも含まれていました。NguyenはPermisoの当初の仮説を、脆弱性を示すツールから能動的な攻撃を検出し対応を支援する製品へと進化することを見つけることだと説明しました。
Okta moves beyond the login screen
従来のアイデンティティおよびアクセス管理製品は、アカウントがアプリケーションにアクセスを許可されるかどうかを判断します。Permisoはアクセスが付与された後のアイデンティティを追跡し、アイデンティティプロバイダー、クラウドインフラ、ソフトウェアサービス、開発システムにまたがる行動を相関させます。
この区別は、企業が人の操作なしにツールを使いデータにアクセスしアプリケーション間で動作できるサービスアカウントやAIエージェントを導入するにつれて重要性を増しています。過剰な権限を持つエージェントは、侵害された従業員アカウントと同等の運用リスクを生み出す可能性があり、その活動は従来の認証製品が解釈するようには設計されていませんでした。
Oktaによれば、Permisoは行動分析と70以上のアイデンティティパートナーにわたる2,500超のリサーチ主導のシグナルを使用しているといいます。これらのシグナルは、未使用の権限、異常なエージェントの活動、ポリシー違反、そして潜在的に広範囲に影響を与える行動をカバーしています。これらの数値はOktaとPermisoが提供したものです。
Permiso's Universal Identity Graph was designed to connect accounts belonging to the same person or machine across infrastructure, software and identity systems. That can allow an investigation to follow an attacker who authenticates through an identity provider, assumes a cloud role and moves into a software application without treating each step as an unrelated alert.
Okta plans to combine those runtime detections with its identity security posture and threat-response products. Okta Chief Product Officer Ely Kahn said Permiso would also add threat researchers to Okta's security operation. Kahn joined Okta in 2026 after serving as chief product officer at SentinelOne and previously co-founding Sqrrl, a threat-hunting provider acquired by Amazon Web Services.
Oktaは、このランタイム検出を自社のアイデンティティセキュリティポスチャーおよび脅威対応製品と組み合わせる計画です。OktaのChief Product OfficerであるEly Kahnは、PermisoがOktaのセキュリティオペレーションに脅威リサーチャーを加えるとも述べました。KahnはSentinelOneでChief Product Officerを務め、その前にはAmazon Web Servicesに買収された脅威ハンティングプロバイダーSqrrlの共同創業者でもあり、2026年にOktaに入社しました。
Okta stated directly that the acquisition will expand its footprint into the core Security Operations Center. That puts the identity provider in competition for budget held by CISOs and security operations leaders, alongside its established authentication, governance and access-management products.
Oktaは今回の買収によりコアとなるSecurity Operations Centerへの足跡が拡大すると明言しました。これにより、同社は既存の認証、ガバナンス、アクセス管理製品と並んで、CISOやセキュリティオペレーション責任者が管理する予算を巡る競合に入ることになります。
The Permiso agreement follows Okta's acquisition of Axiom Security, which added privileged access management for cloud infrastructure, databases and software services. An Okta regulatory filing valued the Axiom purchase consideration at $54 million. Together, Axiom and Permiso fill two adjacent gaps: controlling privileged access and detecting abuse after access has been granted.
Permisoとの合意は、クラウドインフラ、データベース、ソフトウェアサービス向けの特権アクセス管理を追加したAxiom Securityの買収に続くものです。An Okta regulatory filing はAxiomの買収対価を5,400万ドルと評価しました。AxiomとPermisoは合わせて隣接する二つのギャップを埋めます:特権アクセスの制御と、アクセス付与後の悪用検出です。
Permiso raised $28.5 million
Permiso emerged from stealth in January 2022 with a $10 million seed round led by Point72 Ventures. Foundation Capital, Work-Bench, 11.2 Capital and Rain Capital also participated, alongside security executives including former Netflix security leader Jason Chan and Databricks product-security leader Travis McPeak.
Permisoは2022年1月にステルス状態から公に姿を現し、Point72 Venturesが主導した[$10 million seed round]でスタートしました。Foundation Capital、Work-Bench、11.2 Capital、Rain Capitalも参加し、元Netflixのセキュリティ責任者Jason ChanやDatabricksのプロダクトセキュリティ責任者Travis McPeakらセキュリティ幹部も出資に名を連ねました。
Altimeter Capital led Permiso's $18.5 million Series A in April 2024, with Point72 Ventures returning. That brought Permiso's publicly announced funding to $28.5 million.
Altimeter Capitalは2024年4月のPermisoの[$18.5 million Series A]を主導し、Point72 Venturesが再参加しました。これによりPermisoの公表された資金調達総額は2,850万ドルになりました。
At the time of the Series A, Permiso said it had signed multiple six- and seven-figure licenses with Fortune 500 customers. Permiso and Okta have named Autodesk as a customer, while Permiso's public materials have also identified ACV Auctions and Nutanix as users. Permiso has not published revenue or annual recurring revenue.
Series Aの時点で、PermisoはFortune 500企業との間で複数の6桁および7桁のライセンス契約を締結したと述べていました。PermisoとOktaはAutodeskを顧客として名指ししており、Permisoの公開資料ではACV AuctionsやNutanixもユーザーとして挙げられています。Permisoは収益や年間経常収益(ARR)を公開していません。
The agreement is expected to close during the third quarter of Okta's fiscal 2027, subject to customary closing conditions. Okta said the transaction will not change the financial guidance it issued on May 27th.
この合意は、通常のクロージング条件を前提にOktaの2027会計年度第3四半期中に完了する見込みです。Oktaは本取引が5月27日に発表した財務ガイダンスを変更することはないと述べました。