For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/what-is-crowdstrike-agentic-identity-provider.md.
AI Security ↗

What is CrowdStrike Agentic Identity Provider?

Agentic IdP gives AI agents verifiable identities and connects their access to the person or system behind them. Here is how it relates to Guardian and Continuous Identity.

CrowdStrike logo

In brief: CrowdStrike Agentic Identity Provider, or Agentic IdP, establishes verifiable identities for AI agents and links their actions to the person or system they represent. CrowdStrike announced it on 2 September 2026 as part of Falcon Next-Gen Identity Security. The Agentic IdP announcement

An identity provider establishes who or what is requesting access. For an AI agent, the useful distinction is between the software performing an action and the person who asked it to act. A shared credential can blur those two identities. CrowdStrike’s design gives the agent its own identifiable place in the access process. Agent identities in Falcon Next-Gen Identity Security

From discovery to time-limited access

CrowdStrike describes four connected functions:

  1. Register the agent. Falcon Guardian discovers agents; Agentic IdP registers them in a directory.
  2. Establish a verifiable identity. Cryptographic verification provides a basis for checking which registered agent is requesting access.
  3. Broker limited access. Short-lived tokens restrict access to the scope and duration needed for a task.
  4. Preserve attribution. The agent’s actions stay associated with the human or workload behind them, including when work is delegated.

From discovery to accountable access

  1. Discover agents Falcon Guardian

    Find agents and identify who owns or uses them.

  2. Register identity Agentic IdP

    Give each registered agent a verifiable identity.

  3. Broker limited access Agentic IdP

    Use short-lived credentials with a defined scope.

  4. Preserve attribution Identity context

    Link actions and delegation to the person or system behind them.

Continuous Identity re-evaluates what the agent may access and do.

Simplified illustration by FM CyberSecurity, based on CrowdStrike’s description of Agentic IdP. Source: CrowdStrike ↗

These are the functions described in CrowdStrike’s Agentic IdP explanation. Here, a token is an access credential. It is different from the tokens used to measure a language model’s input and output.

Identity and permission answer different questions

Agentic IdP establishes the agent’s identity. Continuous Identity evaluates what it may do using current identity, device, threat and business context. CrowdStrike introduced Continuous Identity for AI Agents in June 2026, before the September IdP announcement. The June announcement

CrowdStrike gives a useful example: an agent capable of reading and writing, acting for a user who only has read access, should only be allowed to read. Its technical capability does not automatically grant it the user’s missing permission. The same access model re-evaluates authorisation when relevant conditions change. CrowdStrike’s explanation of agent authorisation

How it relates to the other announcements

Falcon Guardian supplies discovery and security context about agent activity. Agentic IdP concerns the agent’s identity and access. SafeMind uses offensive and defensive AI for security work. These are related roles, rather than three names for the same product.

Our Fal.Con Las Vegas roundup explains where Agentic IdP fits among the event’s AI security announcements.

← Back to all insights
Questions or inquiry? [email protected] Contact us →