Okta expands its partnership with Google Cloud with new security integrations for AI agents and browser-based work. This move extends identity controls across Google Cloud’s Gemini Enterprise Agent Platform and Chrome Enterprise.
The partnership is aimed at organizations deploying AI agents more broadly while moving day-to-day operations to a browser-based software environment. It combines Okta’s identity products with Google Cloud services designed to manage access, device state, and user activity.
At the heart of the announcement is a set of AI agent integrations built on the Gemini Enterprise Agent Platform. Okta’s Auth0 for AI agents is now integrated with the agent runtime on the platform, allowing developers to add authentication and access control to agent-based workflows.
Services include user authentication, storage and management of OAuth tokens with a token vault, authorization checkpoints for high-risk actions, fine-grained authorization controls, and model context protocol server authentication. The goal is to allow the agent to act on behalf of the user under tighter control and more clearly limit what the user is allowed to do.
The second layer of integration is yet to come. Okta for AI Agents connects with the Gemini Enterprise Agent Platform to provide enterprises with a centralized registry of agents, link each agent to a human owner, and enforce enterprise policies on agent access through the Google Agent Gateway.
These planned controls are intended to address visibility and governance issues as companies move from small pilots to larger deployments. Centralized monitoring becomes difficult when enterprises manage tens of thousands of agents across a variety of systems and tools.
growing concern
The broader context is the rapid rise in the use of AI in the workplace and the parallel rise in identity-based attacks. Okta cited numbers showing that while 92% of executives report moderate or extensive use of AI agents, only 34% of organizations apply the same security controls to agents as human employees.
It also noted a 127% year-over-year increase in identity-based attacks such as session hijacking, where attackers steal post-authentication session tokens held in browsers. This makes browser security a priority for businesses that rely heavily on Software-as-a-Service tools and AI-enabled applications.
In response, Okta and Google Cloud also announced a series of actions related to Chrome Enterprise. This includes Chrome Enterprise Universal Enrollment through the Okta Integration Network, which allows IT teams to apply managed Chrome profile policies to managed and unmanaged devices without syncing identities to Google.
Okta also integrates Device Assurance with the Chrome Device Trust Connector, which allows you to check the health of your browser and device in real-time before allowing access to Okta-protected applications. A new antivirus signal allows Chrome to block logins at the browser level if your antivirus software is disabled or outdated.
Browser mitigations also include support in Chrome for Apple’s Enhanced Single Sign-On on macOS using Okta as the identity provider. Chrome users will now be able to take greater advantage of Okta FastPass and Okta Device Access while signing in between applications.
Another feature is support for Device Bound Session Credentials, an open standard that cryptographically links sessions to specific devices through the Chrome browser. Okta said it worked with Google Cloud as a standard design partner to add support for Okta end-user dashboards to reduce the risk of stolen cookies being reused on another device.
Dan Mountstephen, senior vice president and general manager of Okta APJ, commented on the regional importance of this partnership.
“We are at a pivotal moment across Asia-Pacific. Organizations have moved past the experimental phase of AI. AI agents are now embedded in daily operations as part of the workforce. These agents require the very same governance, visibility, and control that we have applied to human identity for years. This is non-negotiable.”
“But there is another reality we are seeing: Our customers are not tied to a single AI platform or cloud provider. They have multiple environments and tools and want the freedom to choose the best solution without introducing new silos or vendor lock-in.”
“That’s exactly why this partnership is so important. Okta and Google Cloud will enable organizations to deploy AI at scale and securely, with accountability built in from day one, while maintaining the interoperability and choice that drives true innovation. Sustainable AI isn’t about betting everything on one ecosystem; it’s about giving organizations the control, visibility, and flexibility to build what they need,” said Mountstephen.
Okta also said the deal was structured with concerns about dependence on a single provider in mind, with 62% of IT leaders viewing vendor lock-in as a strategic risk. The company argued that enterprises want to combine various AI, cloud, and productivity tools while maintaining a single identity layer across those environments.
“Organizations don’t have to choose between the AI and productivity tools their teams want and the security their business needs,” said Ely Kahn, chief product officer at Okta.
“Securing AI-powered enterprises requires an identity security layer that works seamlessly across the core platforms that power modern operations,” said Vineet Bhan, director and global head of security and identity ISV partnerships at Google Cloud.
