SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Quest expands identity security for AI agent threats

Quest expands identity security for AI agent threats

Wed, 30th Sep 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

Quest Software has expanded its Security Management Platform to cover the full NIST Cybersecurity Framework lifecycle, targeting identity threats linked to human, non-human and AI agent accounts.

The update adds five features focused on identity visibility, attack containment and recovery for Microsoft Active Directory and Entra ID environments. They are intended to help organisations identify what different identities can access, isolate compromised identities during an attack and restore core identity systems more quickly after an incident.

Quest argued that identity has become a central point of risk as businesses give more software agents access to systems and data. Traditional endpoint detection, SIEM and backup products, it said, were not designed to operate inside the identity layer that controls access across many enterprise environments.

One of the new products, Quest Identity Insights, uses technology gained through Quest's acquisition of Anetac. It is designed to continuously map what human, non-human and agentic identities actually access and show access paths to critical systems that may not appear in periodic scans or configuration reviews.

Another feature, Agentic AI Defence, is designed to isolate a compromised identity while an attack is under way, allowing security teams to stop further destructive changes while analysts investigate.

Secure Replay, which is in private preview, uses AI to separate malicious changes from legitimate activity during recovery. Quest said this is intended to help organisations recover to the last known safe state rather than simply reverting to an older backup.

Quest also introduced Guardian Managed Recovery Services, giving customers and partners access to specialist support for preparing and carrying out Active Directory and Entra ID recovery. The service is also available in a fully managed form that partners can offer under their own brand.

A fifth addition, Secure Migration, brings identity threat signals into migration projects. According to Quest, it can flag excess privileges, stale accounts and vulnerable devices before cutover during consolidations and mergers, which the company described as periods of heightened attacker interest.

The expansion reflects a broader shift in cybersecurity towards identity protection as organisations deploy more automated software systems. In many large companies, Active Directory and Entra ID remain the main control points for access, making them attractive targets for attackers and a critical focus for recovery planning.

Quest cited its own research showing that more than 75% of organisations do not have a tested recovery plan for identity systems. It also said its identity security technology can improve recovery time by up to 90% compared with enterprise backup tools.

Tim Page, Chief Executive Officer of Quest Software, linked the launch to concerns about how AI agents can misuse access if they are compromised or poorly governed.

"The OpenAI and Hugging Face incident was the first of many warnings to companies that any AI agent in your enterprise can cause a serious breach," said Tim Page, Chief Executive Officer of Quest Software.

"AI has created an identity security crisis, exposing the limits of legacy systems and making modern resilience an urgent priority. The leaders that prioritise this now are the ones that will lead the agentic era with confidence," Page said.

Microsoft, whose identity products sit at the centre of many corporate technology estates, also commented on the development.

"Identity has become the front line of security in the AI era, and defending it takes a strong ecosystem of partners building alongside Microsoft," said Edwin Vargas, Managing Director, Americas - AI Business Solutions and Security Partnerships at Microsoft.

Quest said the platform is aligned with the NIST framework, which is increasingly used by businesses and public bodies as a structure for cyber risk management. It also said it supports proposed US legislation that would direct NIST to develop standards and guidance for the secure deployment of AI agents, including continuous inventory controls and records of agent activity.

Rakesh Shah, Vice President of Product Management and Marketing at Quest Software, said the company's focus is on helping security teams understand access in real time and act before an attack spreads.

"Companies need to know in real time who has the keys to their systems, which doors they can open and how to take those keys away before the damage spreads," said Rakesh Shah, Vice President of Product Management and Marketing at Quest Software.

"AI agents can hold credentials, reach sensitive systems and act at machine speed. If an agent can be given the keys to the business, security teams must be able to see what it is doing, stop it immediately and recover confidently from whatever it changed," Shah said.