Okta Acquires Permiso to Hunt Attackers Who Are Already Inside
The deal signals a fundamental shift in identity security: controlling the login is no longer enough. Defenders must also watch what happens after the door opens.

Okta has agreed to acquire Permiso, a specialist in detecting suspicious behaviour inside authenticated sessions, in a move that extends the identity giant's reach beyond login control and into post-authentication threat detection.
What is Okta buying, and why does it matter?
Okta manages who is allowed into corporate software. Permiso watches what those users do once they are in. Together, they address the full identity attack surface: authentication at the gate and behaviour monitoring on the inside.
Most modern breaches do not begin with a technical exploit. Stolen credentials, hijacked session tokens, and phished one-time codes hand attackers a valid identity. Once inside, they look indistinguishable from the employee whose account they took. According to the Verizon 2024 Data Breach Investigations Report, credentials are involved in the majority of web application breaches, and detection of abuse after initial access remains one of the hardest problems defenders face.
Permiso fills that gap by analysing behaviour patterns: an account downloading thousands of files at 3 a.m., accessing systems it has never touched before, or exporting a customer list seconds after logging in from an unfamiliar country. None of those actions necessarily trip a traditional login alert. All of them are flags that something is wrong.
How did attackers expose the gap that Permiso addresses?
The identity-based attack pattern Permiso targets is not theoretical. Threat actors have repeatedly demonstrated that owning a valid session token is operationally equivalent to owning the account itself.
Okta itself knows this from painful experience. In October 2023, attackers accessed Okta's support case management system using a stolen credential. The access went undetected long enough for the adversary to view files belonging to 134 customers. The incident is a clean example of exactly the detection problem Permiso is designed to solve: the login was legitimate, but the behaviour was not.
The category Permiso sits in, called identity threat detection and response (ITDR), exists precisely because traditional security information and event management tools were not built to reason about whether a valid, authenticated user is acting like themselves. ITDR tools build a behavioural baseline for each identity and alert when that identity starts acting out of character.
What does the acquisition mean for the identity security market?
The deal positions Okta to compete directly with vendors that already bundle access control and post-login monitoring in one product. For organisations buying security tools, consolidation at this level can simplify architecture and reduce the number of vendors holding sensitive identity data.
No purchase price has been disclosed. No regulatory approval timeline has been made public. Product integration will take time, and customers are unlikely to see material changes to their existing Okta experience in the short term.
For organisations that use neither product today, the announcement is a market signal. Procuring access management and behavioural analytics from separate vendors may become a less common architecture as identity platforms absorb ITDR capabilities.
| Layer | What it covers | Okta's position before deal | Okta's position after deal |
|---|---|---|---|
| Authentication | Who can log in | Core product | Unchanged |
| Session monitoring | What happens after login | Not covered | Covered via Permiso |
| Behavioural baselining | Whether actions match the user's history | Not covered | Covered via Permiso |
| Threat response | Automated action on anomalous sessions | Partial (policy-based) | Expanded |
Which security controls failed in identity-based attacks, and what should defenders do?
Post-authentication detection failures share a common root. Organisations invest heavily in multi-factor authentication (MFA) and single sign-on, then assume the security problem is solved once the user has logged in. It is not.
NIST Special Publication 800-207 on Zero Trust Architecture makes the principle explicit: no implicit trust should follow a successful authentication. Every request, every action, every data access should be evaluated against context. That is the architectural philosophy Permiso operationalises.
In practice, several controls are consistently missing in organisations that suffer post-authentication compromise. Privileged accounts often lack continuous session monitoring. Logs are collected but not analysed for behavioural deviation. Incident response playbooks assume the attacker broke in, not that they walked in.
At the human layer, the problem runs deeper. Security-awareness practitioners observe, repeatedly, that employees share session tokens without recognising the risk, click links in convincing internal-impersonation emails, and fail to report odd behaviour on their own accounts because they assume IT will notice first. Reporting culture matters as much as detection tooling. An employee who notices their account was accessed from a city they have never visited, and who knows who to call in the next five minutes, is a control that no SIEM replicates.
Organisations serious about closing this gap should review whether their security standards and policy framework explicitly addresses post-authentication risk, not just access control at the perimeter. Training staff to recognise the signs of account compromise, and to report them immediately, is a foundational layer that sits beneath any ITDR tool.
What should affected organisations do now?
Existing Okta customers should watch the company's integration roadmap for Permiso and evaluate whether their current behavioural monitoring coverage has gaps that ITDR tooling would close. Contract review is reasonable: any organisation with a data-processing agreement with Okta should check what that agreement says about data use when Okta adds a subsidiary.
Organisations not yet using Okta or Permiso should treat this deal as a prompt to audit their post-authentication visibility. Questions worth asking include: How quickly would you detect an authenticated session accessing data it has no business reason to access? What is your mean time to detect a credential compromise that did not trigger an MFA alert? If neither question has a clean answer, the gap is real.
CISA's guidance on phishing-resistant MFA is a useful starting reference, though it addresses authentication rather than post-authentication monitoring. Pairing MFA hardening with behavioural detection is the architecture defenders should be building toward.
How to reduce your exposure to post-authentication identity attacks
- Train staff to recognise the signs of account compromise, including unfamiliar login notifications and unexpected password-reset emails, and to report them immediately to IT.
- Audit your post-authentication monitoring: verify that your SIEM or ITDR tooling alerts on behavioural anomalies, not just failed logins.
- Review privileged account policies to ensure that high-value identities have session-level monitoring, not just MFA at the gate.
Train2Secure's security-awareness programmes build the reporting habits that give your ITDR tooling something to work with, because detection only succeeds when staff and systems work together.
Start free, no card requiredSources & further reading
Frequently asked questions
What is identity threat detection and response (ITDR)?
ITDR refers to tools and practices that monitor authenticated user sessions for behaviour that deviates from a known baseline, flagging actions that suggest a legitimate account has been compromised even though the login itself succeeded.
Why is monitoring after login more important than just enforcing MFA?
MFA protects the authentication step, but attackers who steal a valid session token bypass it entirely. Post-authentication monitoring catches suspicious behaviour, such as bulk data exports or access to unfamiliar systems, that occurs after a successful login.
Does the Okta-Permiso acquisition change anything for Okta customers right now?
No immediate product changes apply. The acquisition must clear integration planning before any new capabilities reach customers, so day-to-day login screens and existing contracts remain unchanged in the short term.
How can organisations detect compromised accounts when the attacker is using valid credentials?
Behavioural baselining, continuous session monitoring, and strong incident-reporting culture are the key controls. Employees who report anomalies on their own accounts quickly can cut attacker dwell time before automated tooling even generates an alert.



