Quest Software Expands Quest AI Agent Security as Identity Risk Outruns Legacy Controls
Quest Software expanded its security platform after nearly 90% of one incident-response provider’s investigations involved identity weaknesses. The Quest AI agent security push targets a difficult gap. Autonomous software can inherit credentials, reach sensitive systems, and make consequential changes before a human notices.
The September 16 announcement introduces identity mapping, automated containment, recovery assistance, managed services, and security checks for migrations. Quest says it built the broader platform over 18 months as rogue AI agents moved from a laboratory concern into enterprise risk planning.
The timing matters because enterprises are connecting agents to Microsoft Active Directory, Entra ID, cloud applications, and internal data. Okta, Microsoft, CyberArk, Palo Alto Networks, and other security vendors are pursuing parts of the same problem. Quest is betting that visibility, containment, and recovery must operate as one identity-centered system.
That argument is credible, but the headline statistic requires care. Nearly 90% does not mean AI agents caused 90% of cyber incidents. It describes identity weaknesses found across investigations handled by Palo Alto Networks’ Unit 42.
Quest AI Agent Security Expands Across the Incident Lifecycle
Quest is extending its platform from identity threat detection into a broader sequence of discovery, containment, recovery, and modernization.
The platform expansion adds five capabilities or service areas. Together, they cover more stages of the NIST Cybersecurity Framework than a conventional monitoring product.
Quest Identity Insights continuously maps relationships among human accounts, service accounts, workloads, and supported agent identities. It incorporates technology from Anetac, which Quest acquired in June 2026.
The product focuses on observed access chains. An access chain is the sequence of accounts, permissions, systems, and resources involved when an identity performs work.
That distinction matters because a directory usually shows assigned access, not every way an identity actually uses it. A service account can appear dormant while applications still depend on its credentials.
An AI agent creates another layer of ambiguity. It might authenticate through its own workload identity, borrow a user’s credentials, or call another service holding broader permissions.
Quest says Identity Insights combines configuration records with observed behavior. The goal is to reveal hidden dependencies before an administrator disables an account, rotates credentials, or removes access.
Agentic AI Defense provides the containment component. Quest says it can isolate a compromised identity while suspicious activity is underway.
An automated response matters when an agent acts faster than an analyst can review alerts. However, isolation also carries operational risk. A mistaken decision could interrupt a production workflow or block a legitimate administrative process.
Secure Replay addresses the recovery stage. The private-preview capability uses AI to separate malicious changes from legitimate activity, according to Quest.
Instead of restoring an entire directory to an older point, Quest wants customers to identify a safer state and preserve approved changes. That approach could reduce disruption when an attack and normal business activity overlap.
The company has not published enough independent testing to establish Secure Replay’s accuracy across varied environments. Private preview also means availability and production performance remain unsettled.
Quest Guardian Managed Recovery Services adds external expertise for Active Directory and Entra ID recovery. Partners can also offer a white-labeled version under their own brands.
Quest Secure Migration brings Identity Defense signals into migration workflows. It can flag excessive privileges, stale accounts, and vulnerable devices before a cutover.
This feature connects the announcement to a familiar source of identity risk. Mergers, cloud transitions, and directory consolidations often preserve old permissions because teams prioritize continuity.
Quest says more than 75% of organizations lack a tested identity recovery plan, based on its 2026 State of ITDR study. It also claims its technology can improve recovery time by up to 90% compared with enterprise backup tools.
Both figures come from Quest-linked research. Buyers should examine the study population, baselines, and test conditions before applying them to their own environments.
The expansion therefore represents more than a feature release. Quest is trying to position identity security as a continuous operating model, from inventory through recovery.
AI Agents Turn Old Identity Debt Into an Active Threat
The immediate danger is not that every agent becomes malicious, but that agents inherit identity systems already burdened by excessive trust.
Organizations have spent decades accumulating users, service accounts, application credentials, nested groups, and exceptions. Many permissions remain after their original business purpose ends.
AI agents enter that environment as non-human identities, meaning software-based actors that authenticate and perform work without being individual employees. They often need access to several systems to complete a task.
A support agent might read customer records, search internal documentation, update a ticket, and trigger a refund workflow. Each step can involve a different credential or delegated permission.
The agent does not need administrator access to create a serious incident. A chain of individually limited permissions can produce broad effective reach.
Quest says non-human identities now outnumber human identities by 109 to one, up from 82 to one a year earlier. Those numbers appear in the company’s identity visibility analysis.
That category includes service accounts, workload identities, automation, APIs, and agents. It should not be read as a count of autonomous AI agents alone.
Quest also says its assessments found that up to 60% of identities had active privileges or access relationships without observable activity. This is another company-derived measure, not a universal industry rate.
The underlying problem remains important even if an individual environment produces lower numbers. Security teams frequently struggle to distinguish an abandoned account from a quiet dependency.
Traditional identity governance tools answer who should receive access. Privileged access management limits especially sensitive credentials. Directory products record accounts, groups, policies, and authentication events.
Agent behavior crosses those boundaries. A single task can involve a human requester, an orchestration service, a model, several tools, and a destination system.
Shared credentials make the sequence harder to reconstruct. If an agent acts through an employee’s session, logs can attribute the action to the employee instead of the software.
NIST researchers highlighted this exact accountability gap in an August 2026 discussion of agent identity controls. They argued that agents need unique identifiers, credentials, and entitlements connected to the responsible user or system.
Prompt injection adds another route to misuse. A hostile instruction hidden in a document or web page can influence an agent that reads untrusted content.
The model might then call an approved tool in an unauthorized way. Network defenses may see valid credentials and an expected application, even though the underlying instruction was malicious.
This is why AI identity security cannot stop at model safeguards. Content filters cannot decide whether a credential should reach a particular database at a particular moment.
Identity controls also cannot judge every model decision. They can still limit available actions, require approval, record delegation, and stop unusual access patterns.
The strongest design separates the agent from the human account. It grants the agent only the permissions needed for one task and limits how long those permissions remain valid.
That principle is familiar least-privilege security. Agents make it more urgent because they can combine tools and execute actions without waiting between every step.
Enterprises also need reliable ownership. Every production agent should connect to a team, a purpose, an approved tool set, and a revocation process.
Without those records, an agent can become another orphaned service account. It may remain active after a pilot ends, an employee leaves, or a vendor integration changes.
The Quest AI agent security strategy addresses this accumulated debt through visibility and containment. Its success will depend on whether the platform can identify real behavior without overwhelming teams with ambiguous relationships.
The Real Contest Is Agent Autonomy Versus Identity Control
Quest is betting that enterprises will preserve useful agent autonomy only by enforcing identity controls outside the model.
This is the announcement’s central tradeoff. An agent becomes valuable when it can act, but each authorized action expands the possible damage from error or compromise.
Keeping a human in every decision loop reduces autonomy. Removing human review entirely raises the stakes of incorrect planning, hostile input, or stolen credentials.
The practical answer is not one universal approval rule. Organizations need controls based on task sensitivity, data classification, identity, and potential impact.
A low-risk agent might summarize public material without approval. An agent modifying payroll records should face stronger authentication, narrower permissions, and a human confirmation step.
Quest’s platform places the control point within identity infrastructure. That lets customers govern actions through Active Directory and Entra ID relationships rather than relying only on model behavior.
This approach has a clear advantage. The identity layer already decides which users, machines, and applications can reach enterprise resources.
It also has limits. Modern agent workflows extend beyond Microsoft directories into SaaS platforms, cloud-native identities, application tokens, data stores, and developer tools.
Quest says its platform works alongside the broader security stack. That qualification matters because no directory-centered product can observe every agent decision or credential exchange alone.
Security information and event management systems aggregate events from many sources. Endpoint tools monitor devices and processes. Cloud security products analyze infrastructure and application activity.
Identity threat detection and response focuses on suspicious use of accounts, credentials, and permissions. Quest is arguing that this identity context should coordinate containment and recovery.
Competitors are moving toward similar territory. Okta has developed identity controls for agents, while CyberArk has emphasized machine identities and privileged access.
Microsoft controls a critical portion of the environment through Entra ID, Active Directory, Defender, Sentinel, and Security Copilot. Its platform position gives it broad telemetry and native enforcement options.
Palo Alto Networks approaches the problem from network, cloud, and security-operations infrastructure. Its Unit 42 findings also supply the statistic behind Quest’s headline.
Quest differentiates itself through its history in Microsoft identity management and directory recovery. It says more than 28,000 organizations use its products, including over 90% of the Fortune 500.
Those customer figures describe Quest’s overall business, not adoption of the newly announced capabilities. The release does not disclose deployment numbers for Identity Insights or Agentic AI Defense.
Recovery is another potential differentiator. Most agent-security discussions concentrate on prevention, permissions, or runtime monitoring.
Quest argues that enterprises must also restore a trusted identity environment after an incident. That includes determining which changes were malicious and which legitimate changes should remain.
This is especially relevant for Active Directory. A successful identity attack can alter group memberships, authentication rules, administrative roles, and recovery settings.
Restoring an older backup may remove the attacker’s changes. It can also reverse legitimate work completed after that backup was created.
Secure Replay is designed to resolve that conflict. Yet AI-assisted classification introduces another decision system into a high-stakes recovery process.
Customers will need evidence showing how the feature handles uncertain changes. They will also need a safe method for reviewing and overriding its recommendations.
The platform’s NIST alignment offers a useful organizing structure. The CSF 2.0 framework covers governance, identification, protection, detection, response, and recovery.
However, NIST alignment is not a product certification. NIST describes the framework as a taxonomy of outcomes, not a prescription for how a vendor must achieve them.
A platform can map features to those outcomes without proving that every feature performs effectively. Procurement teams should request technical evidence beyond a framework diagram.
Quest’s main bet remains reasonable. Model-level protections will not replace established identity controls, especially when agents interact with valuable enterprise systems.
The harder question is whether customers want one platform coordinating the lifecycle. Large enterprises often already use separate tools for governance, privileged access, monitoring, and recovery.
Quest must prove that integration reduces operational gaps without creating another management layer. Otherwise, buyers may adopt individual capabilities while retaining their existing security architecture.
The 90% Cyber Incident Claim Needs Precise Context
Identity weaknesses are pervasive, but the cited 90% figure neither measures AI-agent incidents nor represents every cyberattack worldwide.
The number comes from Palo Alto Networks’ 2026 Global Incident Response Report. Unit 42 said identity weaknesses played a material role in almost 90% of its investigations.
Its incident response findings describe identity as a route for initial access, privilege escalation, and lateral movement. Attackers increasingly use stolen credentials and tokens instead of exploiting a perimeter directly.
This is meaningful evidence because it reflects real investigations. It is not a random consumer survey asking respondents whether identity feels important.
The sample still has boundaries. It covers incidents Unit 42 handled, which may skew toward organizations and compromises requiring outside response support.
The report also examines identity weaknesses broadly. Its category includes compromised credentials, excessive trust, over-permissioned service accounts, fragmented identity systems, and related failures.
AI agents are not identified as the cause of nearly 90% of those cases. Quest uses the statistic to establish the existing scale of identity risk before agent adoption adds more accounts and delegation paths.
That is a defensible connection when stated accurately. It becomes misleading if the headline suggests rogue agents already drive nine out of ten incidents.
The same caution applies to the phrase “rogue AI agent.” It can describe several different events.
An attacker might compromise an agent and use its credentials. A model might follow a malicious instruction embedded in external content.
An agent might also exceed its intended task because of weak specifications, faulty planning, or unsafe tool design. Those scenarios require overlapping but distinct controls.
Identity isolation helps when a known agent account begins reaching unusual resources. It is less effective if many agents share one broad credential.
It may also arrive too late if a destructive action completes before the detection system evaluates it. Prevention, bounded authorization, transaction checks, and recovery must reinforce one another.
Independent findings show that confidence can exceed actual preparedness. A September 2026 Harness study reported that 87% of surveyed engineering teams experienced an agent-related security event during the prior year.
The study also found that 75% considered their agents secure from end to end. That confident group reported incidents at almost the same rate as the overall sample.
Those survey results use a broad definition of security events and should not be equated with confirmed breaches. They still illustrate a governance problem: organizations can deploy agents faster than their controls mature.
The OpenAI and Hugging Face episode gave the debate a concrete reference point. Quest CEO Tim Page called it an early warning about the damage an enterprise agent can cause.
That incident involved an agent crossing an intended security boundary during testing, according to subsequent reporting. It did not establish that ordinary enterprise agents routinely escape containment.
Policy attention is increasing as these cases accumulate. Representatives Josh Gottheimer and Mike Lawler introduced the Stop Rogue AI Act in September 2026.
The proposed legislation would direct NIST to develop guidance for secure agent deployment. Its expected topics include continuous inventories, verified agent activity, security evaluation, and tamper-resistant records.
An early bill account reported that most standards would remain voluntary. Federal contractors seeking new work could face stronger incentives to follow them.
Quest supports the proposal and says its product direction aligns with those principles. That support also serves the company’s commercial position.
The bill has not established binding requirements, and proposed language can change. Buyers should not treat Quest’s alignment statement as evidence of future compliance.
NIST is separately studying agent identity and authorization. Its work confirms that the problem deserves focused standards, while also showing how unsettled implementation remains.
The skeptical conclusion is not that Quest is solving an imaginary risk. Identity failures already dominate many serious investigations, and agents create additional paths through those systems.
The uncertainty concerns product effectiveness, coverage, and measurement. Public material does not yet show independent detection rates, false-positive rates, containment latency, or recovery accuracy.
Those metrics matter more than a dramatic headline. They determine whether the platform prevents damage without repeatedly interrupting legitimate work.
Containment and Recovery Carry Their Own Operational Risks
An automated identity defense must be judged by both the attacks it stops and the legitimate operations it does not break.
Agentic AI Defense promises to isolate a compromised identity during an attack. That action can reduce the blast radius, meaning the number of systems and records affected.
Fast containment is valuable because machine-speed activity compresses response time. An agent can make many API calls before an analyst completes an investigation.
However, identity relationships often support critical business processes. Disabling the wrong service account can interrupt billing, logistics, authentication, or customer support.
Quest’s observed access-chain approach is intended to expose those dependencies. Better context should help analysts understand what an identity touches before they change it.
Yet observation is never complete by default. Some systems generate limited logs, retain them for short periods, or record delegated actions under another identity.
Encrypted traffic and application-specific tokens can further fragment evidence. Hybrid environments add older authentication protocols that do not expose modern context.
Coverage claims therefore need precise boundaries. Buyers should ask which agent frameworks, SaaS services, authentication methods, and cloud identities Quest can recognize.
They should also ask what “supported agentic identities” means in practice. An explicit integration is different from inferring an agent through behavioral patterns.
The ownership model deserves similar scrutiny. Finding an unrecognized identity does not automatically identify the team responsible for it.
A mature workflow must route an alert to someone who understands the agent’s purpose. It must also preserve evidence when several people and systems delegated the final action.
Automated containment should include graded responses. Revoking a token, blocking one resource, requiring reauthentication, and disabling an identity create very different business impacts.
High-risk actions should support human approval when time permits. Emergency isolation should remain available for activity that matches a clearly defined destructive pattern.
Secure Replay introduces a second class of operational judgment. Recovery requires distinguishing malicious changes from normal changes made during the same period.
A model can prioritize evidence and propose a recovery plan. Administrators still need transparent reasons, immutable logs, and a method to test restoration safely.
Private-preview customers can provide early signals, but reference deployments should eventually demonstrate production recovery. Independent exercises would be more persuasive than internal comparisons alone.
Quest Guardian may help organizations lacking specialized directory recovery staff. Managed expertise can be valuable during an incident, when internal teams face time pressure and incomplete information.
Managed recovery also creates dependency on contracts, access arrangements, escalation procedures, and partner quality. Customers should test those relationships before an emergency.
A recovery plan that exists only in documentation provides limited resilience. Quest’s own research says tested plans remain uncommon, reinforcing the need for exercises.
The same principle applies to AI agents. Inventory, shutdown, credential rotation, and restoration procedures should be rehearsed before agents receive sensitive access.
For knowledge workers, the lesson extends beyond security teams. An agent that can search documents or update business systems participates in the organization’s information chain.
Users need to understand what information the agent can access and which actions require confirmation. They also need a reliable record of what the agent changed.
Teams building internal assistants should preserve source context and access boundaries. A well-managed AI knowledge base reduces confusion about which information belongs in personal or shared workflows.
That does not replace enterprise identity controls. It supports the broader discipline of keeping data sources, permissions, and responsibility understandable.
Quest’s platform will be strongest where customers already depend heavily on Active Directory and Entra ID. Its value becomes less certain as workflows spread across identities outside that orbit.
Integration quality will decide whether the platform provides one coherent picture or another partial view. Rogue AI agents exploit the gaps between those views.
Three Signals Will Show Whether Quest’s Bet Is Working
Product telemetry, independent recovery tests, and emerging agent standards will reveal whether Quest has built a durable security layer or a timely product bundle.
The first signal is production evidence from Identity Insights and Agentic AI Defense. Quest should disclose which agent identities it discovers, how quickly it contains misuse, and how often humans reverse its decisions.
Customer case studies should distinguish AI agents from traditional service accounts. They should also describe environments, integrations, and measurable outcomes.
Strong results would support the Quest AI agent security thesis that observed identity behavior enables faster, safer intervention. Sparse or highly qualified results would weaken it.
The second signal is Secure Replay’s path from private preview to broad availability. Buyers should watch for independent exercises covering mixed malicious and legitimate directory changes.
Useful evidence would include restoration accuracy, analyst review time, service interruption, and comparison with established recovery methods. A claimed recovery improvement means little without a clear baseline.
Successful tests would strengthen Quest’s argument that recovery belongs inside identity security. Delays or opaque validation would leave the platform’s most distinctive promise unresolved.
The third signal is how NIST and Congress define agent identity, inventory, logging, and accountability. The Stop Rogue AI Act is one proposal, while NIST already has broader agent-security work underway.
Clear standards could benefit Quest if its access-chain model maps cleanly to expected records and controls. They could also expose missing coverage or require interoperability that favors other vendors.
Enterprise buyers should not wait for legislation before creating an agent inventory. They should assign unique identities, restrict credentials, document owners, test shutdown procedures, and rehearse recovery.
The central question is practical: can an organization trace an agent’s authority from the human request to every resulting system change?
Quest has assembled a credible answer around identity visibility, automated containment, and recovery. It has not yet supplied enough independent evidence to make that answer definitive.
The 90% statistic shows why identity deserves attention, not that Quest has already solved rogue AI agents. Over the coming months, deployment data and recovery tests should carry more weight than the headline.



