InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

MFA For Machines: The next evolution in non-human & agentic AI identity security

Presented by

Apurva Dave and Dan Kaplan

About this talk

The number of non-human identities (NHIs) is growing 2.5x every year, and the ratio of NHIs to human identities is now 45:1. This explosion – now accelerating as organizations adopt agentic AI workloads – has created a massive, unprotected attack surface. While we rigorously secure human access with multifactor authentication (MFA), the workloads, services, APIs, and AI agents they build are often left vulnerable, secured only by static, easily stolen credentials. Breaches at companies like Snowflake and Microsoft have shown that attackers are actively targeting this weakness. Join us for a timely session on why applying MFA principles to your non-human workloads – including agentic AI – is the essential next step in your security strategy. We'll move beyond theory and break down how to implement strong, automated authentication for machines and AI-driven agents, without slowing your developers down. Expect tactical takeaways on: - Why "Something You Know" is the weakest link for both human and machine identities and how to fix it. - How to apply the principles of MFA to workloads in diverse environments, including Cloud, On-Prem, Serverless, SaaS – and AI agents. - Real-world examples of how stolen non-human credentials led to significant breaches. - Actionable methods for implementing MFA for machines using factors like cryptographically verifiable identity documents, hardware fingerprints, and posture assessments. - How to move past risky, long-lived secrets to a modern approach using short-lived, just-in-time tokens without manual intervention. Whether you're in DevOps, DevSecOps, or Identity and Access Management, this session will give you a practical framework for securing the massive landscape of non-human and AI workloads – without sacrificing velocity.
EC-Council | Security Channel

EC-Council | Security Channel

49715 subscribers82 talks
For Certified Members and Information Security Professionals Globally
The International Council of E-Commerce Consultants (EC-Council) is a member-based organization that certifies individuals in various e-business and security skills. It is the owner and developer of the world famous Certified Ethical Hacker (C|EH), Computer Hacking Forensics Investigator (C|HFI) and EC-Council Certified Security Analyst (E|CSA)/License Penetration Tester (L|PT) programs, and various others offered in over 60 countries around the globe.
Related topics