Identity · Idira

Identity Security
The Human + Machine + Agent Perimeter

The largest acquisition in Palo Alto Networks history brings identity to the platform. CyberArk closed Feb 11, 2026 at ~$25B and relaunched as Idira on May 12, 2026 — the next-generation identity security platform built for the AI enterprise, securing every human, machine, and AI-agent identity.

Acquisition

CyberArk Joins Palo Alto Networks — Now Idira

A ~$25B deal closed Feb 11, 2026, rebranded Idira and GA at IMPACT 2026 on May 12, 2026. Identity is now a core platformization pillar.

$25B
Acquisition Value
Feb 11
2026 Close Date
May 12
2026 Idira GA (IMPACT)
80:1
Machine-to-Human Ratio

Why this matters: The ~$25B CyberArk acquisition closed Feb 11, 2026 and is the largest in Palo Alto Networks history — larger than all previous acquisitions combined. The platform relaunched as Idira (formerly CyberArk), GA May 12, 2026 at IMPACT 2026, positioned as the next-generation identity security platform built for the AI enterprise. Identity has become the primary attack surface, with 80 machine identities for every human identity. Confirmed Idira module names: Idira Privileged Access Manager, Idira Secrets Hub, Certificate Manager, Idira Secure AI Agents. A TASE secondary listing is planned under ticker "CYBR".

Deep Dives

Platform Component Deep Dives

Looking for the workforce IAM tier — the piece that competes head-on with Okta? See Idira Workforce Identity for SSO, adaptive MFA, passwordless, Secure Web Sessions, Workforce Password Management, B2B Identity, lifecycle management, the Okta head-to-head matrix, and the three deal shapes.

Click any component to explore detailed capabilities and market context.

Idira (formerly CyberArk) is the consistent Gartner Magic Quadrant Leader for PAM (2025). Automatic discovery of privileged accounts, credentials, IAM roles, and secrets across on-prem, multi-cloud, and OT/ICS environments. Available as PAM-as-a-Service (SaaS) or self-hosted.

Session Recording

Tamper-proof privileged session capture, monitoring, and real-time analytics for forensic audit trails

Just-in-Time Access

Ephemeral elevated privileges granted on-demand, automatically revoked after use — Zero Standing Privilege

Credential Vaulting

Tamper-proof Digital Vault with AI-driven (CORA AI) credential rotation and policy recommendations

Additional: On-Demand Privileges Manager (Unix/Linux privilege elevation) • Intelligent entitlement management • >90% gross retention rate • 400+ channel partners globally • ARR surpassed $1B (early 2025)

Idira Secrets Hub is the confirmed module name for secrets management of non-human credentials and application secrets. Three deployment patterns to fit any architecture:

SaaS delivery

Cloud-native centralized secrets for apps, workloads, DevOps pipelines

Self-hosted delivery

Kubernetes-native, policy-based and API-driven for regulated or air-gapped estates

Cloud vault bridging

Brings native cloud vaults under enterprise governance without re-platforming apps

Integrations: Kubernetes, CI/CD tools (Jenkins, GitHub Actions, GitLab), AWS, Azure, GCP, Terraform. Eliminates hardcoded credentials via Credential Providers.

Machine identity security ships as Certificate Manager. The capability entered the portfolio when CyberArk acquired Venafi for $1.54B (October 2024), expanding the total addressable market to ~$60B. Certificate Manager machine-identity capability is also integrated into NGTS (Next-Generation Trust Security), launched Mar 23, 2026, which adds network-native certificate lifecycle management and SaaS private PKI inside Strata Cloud Manager.

PKI & Certificate Lifecycle

SSL/TLS, SSH, code signing, IoT and mobile certificates — issuance, revocation, renewal

Workload Identity

Cloud-native workload identities via SPIFFE/SPIRE, Kubernetes service mesh integration

Secure Code Signing

Governs software signing processes with SSH key discovery, management, and rotation

Coverage: on-premises, multi-cloud (AWS, Azure, GCP), Kubernetes/containers, IoT devices, mobile, virtual environments. Post-quantum readiness for passwords, secrets, and keys.

Idira (formerly CyberArk) provides enterprise SSO and adaptive risk-based MFA for all workforce users — adjusting authentication strength based on device posture, location, behavior patterns, and session context.

  • FIDO2/WebAuthn passwordless authentication, SAML, OIDC federation
  • Secure Remote Access for vendors, contractors, and third parties — no VPN required
  • CORA AI anomaly detection for risky user behavior and session analytics

Full identity lifecycle management enhanced by the Zilla Security integration. AI-powered access recommendations speed up provisioning, streamline access reviews, and manage permissions. Only 6% of organizations have fully automated IGA — representing a massive greenfield opportunity.

  • Automated provisioning/deprovisioning from onboarding through offboarding
  • Automated access review campaigns with centralized auditing and evidence collection
  • Compliance reporting: SOX, GDPR, HIPAA, and universal app integration (cloud, homegrown, on-prem)

The Idira AI engine (introduced as CyberArk CORA AI) that powers intelligent identity security across the entire platform.

Detect Anomalies

Spots risky identity behavior patterns in real time

Audit Sessions Faster

AI-driven summaries of privileged sessions for rapid forensic review

Automate Confidently

Smart policy recommendations, troubleshooting, and onboarding automation

Palo Alto Ecosystem Integration — what has actually shipped: Idira continues as a standalone platform — no disruption for existing customers. Shipped: Idira Endpoint Privilege Manager integrates with Cortex XSIAM via the Cortex Marketplace (shipped with XSIAM 3.5, May 2026); machine-identity integration into NGTS (Next-Generation Trust Security, launched Mar 23, 2026). Directional: Cortex XSIAM ITDR (identity context in SOC alerts), Prisma Access (ZTNA enriched with privilege controls), Cortex Cloud (CIEM + PAM enforcement), Cortex AgentiX (identity-driven response playbooks). A TASE secondary listing is planned under ticker "CYBR".

Nearly 90% of organizations have suffered an identity-centric breach • TAM expanded to ~$60B • No Palo Alto Networks identity certification exists yet — position Idira enablement through vendor training, not a PAN certification track

Capabilities

The Idira Platform

Comprehensive identity security across every identity type.

Idira Privileged Access Manager goes beyond the narrow admin set — protecting privileged access for all users, not just IT admins. Capabilities include:

Vault & Session Management

Secure credential storage with session recording and monitoring

Just-in-Time Access

Ephemeral elevated privileges that auto-expire after use

Least Privilege Enforcement

Continuous right-sizing of permissions across all accounts

Centralized governance for all identity types. Automate access certifications, enforce segregation of duties, and maintain continuous compliance. Includes role mining, access request workflows, and audit-ready reporting for regulations like SOX, GDPR, and HIPAA.

Automated provisioning and deprovisioning across the entire identity lifecycle — from onboarding through role changes to offboarding. Integrates with HR systems, directories, and cloud platforms. Ensures no orphaned accounts or stale permissions persist after personnel changes.

Enterprise SSO with adaptive MFA that adjusts authentication strength based on risk signals — device posture, location, behavior patterns, and session context. Supports FIDO2/WebAuthn passwordless authentication, SAML, OIDC, and federated identity across multi-cloud environments.

With 80 machine identities for every human, this is the fastest-growing attack surface. Idira Certificate Manager and Idira Secrets Hub secure:

  • Service accounts and API keys across cloud and on-premises
  • Certificates, tokens, and secrets lifecycle management
  • IoT device identities and workload attestation
  • Kubernetes service mesh identity and SPIFFE/SPIRE integration

Idira Secure AI Agents is the confirmed module for the newest frontier in identity security. As autonomous AI agents proliferate, each agent becomes an identity that needs governance: identity provisioning for AI agents, scoped permissions and trust boundaries, behavioral monitoring of agent actions, and revocation controls when agents deviate from expected behavior. This complements the AI Agent Security capability in Prisma AIRS 3.0.

80 : 1

Machine-to-Human Identity Ratio

For every human identity in a typical enterprise, there are 80 machine identities — service accounts, API keys, certificates, bots, and now AI agents. This is why identity became the 4th pillar.

Roadmap

Integration with PAN Ecosystem

How Idira identity capabilities integrate across Cortex and Strata.

Cortex Integration

  • XSIAM ITDR

    Identity threat signals feed XSIAM ITDR; Idira Endpoint Privilege Manager integration shipped with XSIAM 3.5 via Cortex Marketplace

  • Cortex Cloud CIEM

    Cloud identity entitlements enriched with Idira governance data

  • AgentiX Automation

    Automated identity-based response playbooks via agentic AI

Strata Integration

  • NGFW User-ID Enrichment

    Idira identity context feeds NGFW policy enforcement; Certificate Manager machine identity feeds NGTS in Strata Cloud Manager

  • Prisma SASE Identity

    Unified identity-based access policies for ZTNA and GlobalProtect

  • Zero Trust Enforcement

    Continuous identity verification at every network access point

Scoping

Sizing the Identity Opportunity

Key dimensions to scope an identity security engagement.

Identity Count

Total identities: human users, service accounts, machine identities, API keys, and AI agents. Remember the 80:1 ratio — most orgs undercount machine identities by 5-10x.

Current IAM/PAM Tools

What are they using today? Idira/CyberArk (already), BeyondTrust, Delinea, SailPoint, Okta, Entra ID? Capture contract end dates and identify consolidation and upgrade opportunities.

Compliance Requirements

Which regulations mandate identity controls? SOX (privileged access), HIPAA (access logging), PCI DSS (authentication), GDPR (access rights), NIS2 (identity governance)?

Cloud Identity Federation

How are identities federated across cloud providers (AWS IAM, Azure AD, GCP IAM)? Multi-cloud identity sprawl is a key pain point Idira solves.

Pre-Sales

Scoping Checklist

Data points to collect before quoting an Idira identity security engagement.

Identity Counts — Human users, machine identities (service accounts, API keys, certificates) and AI agents, counted separately. Expect machine identities to be undercounted 5-10x against the 80:1 ratio
Privileged Accounts Under Management — How many privileged accounts are vaulted today vs total discovered, as a count; this is the Idira Privileged Access Manager sizing unit
Incumbent PAM and IGA Vendors — Named vendors (BeyondTrust, Delinea, SailPoint, Saviynt, Okta, Entra ID) with annual spend and contract end dates
Secrets Management Current State — Number of secrets, native cloud vaults in use, CI/CD platforms, and count of hardcoded credentials found — drives Idira Secrets Hub scope
Certificate Estate Size — Total TLS/SSH/code-signing certificates, number of issuing CAs, and outage history from expiries — drives Certificate Manager and any NGTS attach
Directory Sources — Which directories are authoritative and their user counts: on-prem Active Directory, Entra ID, Okta, plus HR system of record for lifecycle feeds
Just-in-Time vs Standing Privilege — Percentage of privileged access that is standing today, target zero-standing-privilege date, and number of Unix/Linux hosts needing privilege elevation
Idira Module Selection — Which confirmed modules are in scope: Idira Privileged Access Manager, Idira Secrets Hub, Certificate Manager, Idira Secure AI Agents. Do not quote unconfirmed module names
XSIAM / SOC Feed Scope — Whether identity telemetry feeds Cortex XSIAM ITDR, and whether the Idira Endpoint Privilege Manager integration (Cortex Marketplace, shipped XSIAM 3.5) is required; capture endpoint count for it
Compliance Drivers — Named frameworks and audit dates: SOX privileged access, PCI DSS authentication, HIPAA access logging, GDPR access rights, NIS2 and DORA identity governance, plus any data-residency constraint on the SaaS tenant

Discovery

Identity Security Discovery Questions

Uncover identity blind spots and build the business case.

Why ask: Most organizations only vault 20-30% of their privileged accounts. The rest — shared accounts, service accounts, emergency access — are unmanaged attack vectors.

Listen for: "We don't know" — discovery engagement. "Just our IT admins are managed" — broader PAM expansion.

Why ask: The 80:1 machine-to-human ratio means the real attack surface is non-human identities. Most orgs have no centralized inventory of machine identities.

Listen for: "We track them in spreadsheets" — major governance gap. "Each team manages their own" — silo problem that Idira Secrets Hub unifies.

Why ask: Lifecycle management gaps are a top audit finding. Orphaned accounts with privileged access are among the most common breach vectors.

Listen for: "HR notifies IT and they disable accounts" — manual process with gaps. "We have a 30-day process" — 30 days is an eternity for attackers.

Why ask: Multi-cloud identity sprawl is the norm. Most orgs have separate IAM in each cloud plus dozens of SaaS apps with their own user directories.

Listen for: "We use Azure AD for SSO and each cloud has its own IAM" — federated identity opportunity. "It's a mess" — strong consolidation play.

Why ask: Agentic AI is the next identity frontier. AI agents need identities, permissions, and governance — but most orgs treat them as service accounts without proper controls.

Listen for: "Yes, our AI agents have service accounts" — validate governance. "Not yet" — get ahead of the wave with proper identity frameworks.

Why ask: Identity-based attacks account for 80%+ of breaches. The integration of Idira with XSIAM ITDR provides real-time identity threat detection and automated response.

Listen for: "We rely on failed login alerts" — reactive approach. "Our SIEM handles it" — show how XSIAM ITDR + Idira is purpose-built for identity threats.