Analyst Comment: Why Did Okta Buy Permiso Security?
Okta recently announced they had entered into a definitive agreement to acquire Permiso Security.
How does this fit with their strategy and what does Permiso bring to their stable of identity capabilities?
If we step back a little before diving into Permiso, where are Okta on their strategic journey? They originally were the one of the early identity and access management (IAM) darlings - being a rare public IAM provider, being listed in April 2017. Their valuation has fluctuated since those early days when they had little competition in the cloud single sign on (SSO) space focused on the small to mid-market.
Image Source: Google Finance
Since then, they have undergone a valuation downturn and seen increased competition from a range of positions.
There are numerous triggers for this (the general post-covid tech turn down being one) but also a hack by the LAPSUS$ group in 2022 and the $6+ Billion acquisition of Auth0 in 2021 another. In combination a general slow-but-steady change to a broader identity and security play brought growth - but also challenges.
In 2022 they introduced their identity governance and administration (IGA) capabilities and in December 2023 their privileged access management (PAM) features. Whilst this allowed cross-sell opportunities for existing customers, it would also have broadened their competitive footprint - introducing established and startup players into their field of view.
If we zoom out and take a high level view of B2E (and some B2C) identity life cycle components, Okta has branched away from SSO, IDP and authentication functions into more life cycle, privileged and governance features. The two more recent overlay aspects that have emerged within the broader identity industry since circa 2016 include the identity data and identity runtime components.
In December 2023 Okta acquired Spera in an attempt to tackle some of the data risk requirements - commonly placed in the identity security posture management (ISPM) bucket. Last summer, in August 2025 they also improved and expanded their PAM offering by acquiring Axiom.
Permiso is their most recent acquisition and fits neatly into the identity runtime category - namely identity threat detection and response.
Who Are Permiso?
Permiso have been around about 5 years and have firmly focused on identity behaviour, analysis and runtime response, with strong capabilities within the classic ITDR space. They have experienced founders and have made a strong play on their research - both generating it internally, but also releasing it to the community via a serious of reports, articles and open source tools.
They are strongly experienced and integrated into the security world - from security operations centre usage, but also how they position and navigate their go to market story.
Image Source: The Cyber Hut Matrix Export of Permiso Security
The Okta press release backs this up describing them as:
“Okta announced it has signed a definitive agreement to acquire Permiso Security, a cloud-native identity security platform that detects and mitigates threats across human, non-human, and agentic identities in multi-cloud environments.”
The release goes on to state that:
“With the addition of new identity risk signals, behavioral analytics, and threat detections from Permiso, the Okta Platform will offer comprehensive identity threat detection and response (ITDR) capabilities, helping customers surface identity-related risk faster, remediate vulnerabilities and excessive privileges, and stop attacks across their technology stack”
The Permiso platform fits nicely into what Okta describe as their “identity security fabric” - a loose term that allows for further horizontal and vertical expansion of both data sources but also integration touch points and response features.
As the rise of non-human identity (NHI) and agentic identity increases both risk and opportunities, being able to both monitor and respond at runtime to identity risk becomes table stakes.
Permiso will shore-up the identity data, governance and PAM capabilities Okta has been developing by reducing risk at the post-login account-in-use phase.
The release continues to amplify that Permiso is “…using more than 2,500 research-driven signals across 70+ identity partners, such as overprivileged access, unused permissions, anomalous agent behavior and tool usage, policy violations, and high blast radius behavior, in real time. Once integrated with Okta’s identity security fabric, these capabilities will help organizations mitigate critical operational blind spots by extending advanced runtime detection and response across all identity types.”
Takeaway
Okta has become one of the largest identity players of the past decade - through organic expansion but also via the homegrown addition of what are becoming commodity features alongside subtle acquisitions. Permiso adds a very complimentary set of features focused more on security and runtime behaviour.
It will be interesting to see if their acquisition story is complete, or whether Okta will return in the coming months to expand further into NHI and agentic.
About The Author
Simon Moffatt has over 25 years experience in IAM, cyber and identity security. He is founder of The Cyber Hut - a specialist research and advisory firm based out of the UK. He is author of CIAM Design Fundamentals and IAM at 2035: A Future Guide to Identity Security. He is a Fellow of the Chartered Institute of Information Security, a regular keynote speaker and a strategic advisor to entities in the public and private sectors.







