Netwrix has announced new security capabilities across its software portfolio, introducing enhanced visibility into artificial intelligence agents operating inside Microsoft Entra ID. The updates, integrated into Netwrix PingCastle and Netwrix Threat Manager, give enterprise security teams comprehensive tracking for non-human identities alongside expanded cloud risk assessments.

As organizations rapidly adopt autonomous AI tools and machine learning agents, managing the identities created for these autonomous systems has become a critical challenge. Netwrix aims to resolve this visibility gap by giving security professionals detailed oversight of which AI agents exist and what permissions they hold.

Expanding Enterprise Identity Security

Enterprise environments have seen a major influx of autonomous AI agents designed to handle automated administrative actions, retrieve enterprise data, and communicate with cloud services. However, because many AI tools operate with high-level privileges, they create significant attack vectors when left unmonitored or undocumented.

The latest update expands identity protection beyond traditional user accounts and static service accounts. By extending coverage deep into Microsoft cloud environments, Netwrix helps organizations maintain continuous control over non-human entities. Security administrators can now trace how AI agents interact with corporate infrastructure and ensure those identities align with established compliance and governance frameworks.

Tracking AI Agent Identities in Microsoft Entra ID

A primary objective of the update is providing clear Netwrix Microsoft Entra ID AI agent visibility. Enterprise IT departments frequently struggle to track non-human identities, which can lead to privilege creep and unmonitored access points. Netwrix Threat Manager addresses this issue by automatically generating a complete inventory of AI agents running within Microsoft Entra ID.

Through this inventory mechanism, security analysts can quickly view active agents, audit the permissions assigned to each identity, and verify whether those accounts are properly configured. Jeff Warren, Chief Product Officer at Netwrix, emphasized the importance of this capability, stating that while earlier releases provided visibility into what AI agents could access, the latest update goes a layer deeper to identify which agents exist at all. He noted that fewer than one in five organizations fully govern non-human identities, making discovery an essential step because security teams cannot review access for an identity they do not know exists.

Addressing Governance Challenges in Cloud Environments

Recent industry research indicates a growing disconnect between the speed of AI deployment and the governance practices supporting it. A survey conducted by the Cloud Security Alliance revealed that fewer than a quarter of organizations have formally adopted policies for creating or removing the identities used by their AI systems. Additionally, over 16 percent of surveyed organizations do not track when new AI identities are created.

This lack of visibility carries clear risks. According to the Netwrix Data and Identity Security Report, organizations experiencing a significant expansion of AI-related identities faced a breach rate of 43 percent, compared to just 11 percent for organizations where AI deployment did not expand the identity landscape. Providing security teams with dedicated discovery tools reduces the reliance on manual tracking and minimizes the likelihood of shadow AI identities lingering in cloud networks.

Key Integration Features in PingCastle and Threat Manager

The functionality is delivered through updates across two core security offerings in the Netwrix portfolio. Netwrix PingCastle now includes 102 risk checks dedicated to Microsoft Entra ID, extending its posture assessment framework from on-premises Active Directory into the cloud plane. This unified model enables IT teams to evaluate risk across hybrid environments using a single, prioritized methodology.

Meanwhile, Netwrix Threat Manager incorporates the dedicated AI agent discovery engine, providing actionable context regarding permissions and non-human account risks. In addition to tracking agent identities, Threat Manager introduces specialized protection for Azure Files, enabling security teams to detect ransomware behavior, abnormal user access, and risky configuration modifications such as open file-sharing permissions.

With these updates, Netwrix provides a clearer bridge between legacy directory security and modern cloud identity governance. As autonomous agents become standard components of enterprise workflows, having unified visibility across both Active Directory and Microsoft Entra ID offers organizations a practical way to manage identity risks effectively.