Security

Idira Targets AI Identity Risks in Telecom

LinkedIn Google+ Pinterest Tumblr

CyberArk, now operating under the Idira identity security brand, is targeting a growing communications risk. Modern workplaces now rely on people, service accounts, bots, APIs, and autonomous agents. Each one can touch collaboration tools, contact centers, CRM platforms, and customer data.

That creates a new security problem for communications teams. A login no longer proves that every later action is safe. An assistant may retrieve files, update a case, or trigger a workflow. An administrator may change routing or recording policies for thousands of users.

As a result, identity control must move beyond authentication. It must check what each actor can do, when, and why. It also must revoke access quickly when risk changes.

Palo Alto Networks acquired CyberArk in February 2026. It introduced Idira in May as a broader identity security platform. The platform focuses on human, machine, and AI identities. Its model centers on temporary privilege, ownership, credential protection, and audit evidence.

For telecom and VoIP engineers, this matters in daily operations. A compromised admin account could alter call routing. A service account could expose recordings or customer records. An AI assistant could access CRM, billing, and collaboration data during one task.

Idira aims to reduce that risk by limiting standing access. Instead of permanent rights, users and agents receive task-based authority. The system can also record sessions and support investigations after incidents.

The strongest part of the approach is its focus after login. Many tools confirm identity at the door. Idira tries to monitor privilege during the journey. That is important as communications workflows span many platforms.

However, buyers should test its reach carefully. Communications environments often include mixed UC, contact center, SaaS, and custom systems. Controls lose value when agents or developers can bypass them.

One key area is MCP, or Model Context Protocol. MCP gives AI agents a common way to reach business tools. Idira can place a broker between agents and remote tools. This broker can approve access without exposing credentials.

That model adds useful control. Yet coverage remains the real test. Every unmonitored connector becomes another path to sensitive data. Teams should confirm discovery, approval, logging, and live revocation in real workflows.

The market is also moving fast. Microsoft, Okta, and SailPoint have launched agent identity controls. Idira stands out through its privileged access heritage. Still, leadership depends on integration and field results.

Before adoption, communications buyers should run a proof of concept. They should include admins, service accounts, AI agents, and external connectors. They should measure latency, audit quality, revocation speed, and failure behavior.

Idira does not replace UCaaS, CCaaS, fraud detection, or compliance tools. It protects the identities acting behind those systems. For modern communications, that layer is becoming essential.

Write A Comment