# What is CrowdStrike Agentic Identity Provider?

> Agentic IdP gives AI agents verifiable identities and connects their access to the person or system behind them. Here is how it relates to Guardian and Continuous Identity.

Source: https://fmcybersecurity.com/en/insights/ai-security/what-is-crowdstrike-agentic-identity-provider/
Locale: English
Other locale: https://fmcybersecurity.com/insights/ai-security/hva-er-crowdstrike-agentic-identity-provider/

## Metadata

- Date: 2026-09-17
- Author: kenny-le
- Topic: ai-security
- Format: article
- Partner: crowdstrike

<img src={crowdstrikeLogo.src} alt="CrowdStrike logo" width="320" height="75" style="margin: 0 0 24px; border-radius: 0; max-width: 100%;" />

**In brief:** CrowdStrike Agentic Identity Provider, or Agentic IdP, establishes verifiable identities for AI agents and links their actions to the person or system they represent. CrowdStrike announced it on 2 September 2026 as part of Falcon Next-Gen Identity Security. [The Agentic IdP announcement](https://www.crowdstrike.com/en-us/press-releases/crowdstrike-agentic-identity-provider-foundation-for-ai-agent-identity-security/)

An identity provider establishes who or what is requesting access. For an AI agent, the useful distinction is between the software performing an action and the person who asked it to act. A shared credential can blur those two identities. CrowdStrike's design gives the agent its own identifiable place in the access process. [Agent identities in Falcon Next-Gen Identity Security](https://www.crowdstrike.com/en-us/platform/next-gen-identity-security/)

## From discovery to time-limited access

CrowdStrike describes four connected functions:

1. **Register the agent.** Falcon Guardian discovers agents; Agentic IdP registers them in a directory.
2. **Establish a verifiable identity.** Cryptographic verification provides a basis for checking which registered agent is requesting access.
3. **Broker limited access.** Short-lived tokens restrict access to the scope and duration needed for a task.
4. **Preserve attribution.** The agent's actions stay associated with the human or workload behind them, including when work is delegated.

These are the functions described in [CrowdStrike's Agentic IdP explanation](https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-agentic-identity-provider/). Here, a token is an access credential. It is different from the tokens used to measure a language model's input and output.

## Identity and permission answer different questions

Agentic IdP establishes the agent's identity. **Continuous Identity** evaluates what it may do using current identity, device, threat and business context. CrowdStrike introduced Continuous Identity for AI Agents in June 2026, before the September IdP announcement. [The June announcement](https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-continuous-identity-for-ai-agents/)

CrowdStrike gives a useful example: an agent capable of reading and writing, acting for a user who only has read access, should only be allowed to read. Its technical capability does not automatically grant it the user's missing permission. The same access model re-evaluates authorisation when relevant conditions change. [CrowdStrike's explanation of agent authorisation](https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-continuous-identity-for-ai-agents/)

## How it relates to the other announcements

[Falcon Guardian](/en/insights/ai-security/what-is-falcon-guardian/) supplies discovery and security context about agent activity. Agentic IdP concerns the agent's identity and access. [SafeMind](/en/insights/ai-security/what-is-crowdstrike-safemind/) uses offensive and defensive AI for security work. These are related roles, rather than three names for the same product.

Our [Fal.Con Las Vegas roundup](/en/insights/ai-security/crowdstrike-september-2026-falcon-ai-security-news/) explains where Agentic IdP fits among the event's AI security announcements.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
