Detecting Shadow AI Agents with Advanced Posture Checks
Okta, Tuesday, September 15th, 2026
Okta released 24 osquery detections in Okta Verify to surface unauthorized AI tools running on managed devices.
Okta published a set of 24 osquery-based detections delivered through Okta Verify that identify possible unauthorized AI tools on managed devices.
The detections look for known agent binaries, MCP server processes, and configuration artifacts associated with local AI tooling.
The post explains how results feed device posture signals that can gate access to sensitive applications. It includes guidance on tuning to avoid blocking sanctioned developer workflows.