Netwrix has introduced enhanced capabilities in its Netwrix PingCastle and Netwrix Threat Manager products, aiming to strengthen identity security within the Microsoft cloud ecosystem. These updates, which include support for AI agents, come at a time when organisations are increasingly deploying artificial intelligence at an accelerated pace, often without suitable governance structures in place.
A recent study by the Cloud Security Alliance revealed that under a quarter of organisations maintain formal policies for managing AI system identities. Alarmingly, over 16% fail to track the creation of new identities. Netwrix’s 2026 Data and Identity Security Report highlights the consequences, noting a 43% breach rate where AI-driven identities have expanded, contrasted with 11% in lesser-impacted environments.
Enhanced identity risk checks
The latest iteration of Netwrix PingCastle now extends its coverage to 102 risk checks within Microsoft Entra ID. This enhancement brings its widely utilised Active Directory assessment methods into the cloud domain, allowing security teams to evaluate risks across both on-premises and cloud identities with a unified approach.
Netwrix Threat Manager has been upgraded to provide greater visibility into AI agent identities within Microsoft Entra ID. By furnishing an inventory of active agents and their accesses, this development delivers a long-missing foundational element for organisations. According to Netwrix, just 19% of firms fully govern non-human identities like AI agents, highlighting the importance of this improvement.
Advanced threat detection features
Netwrix Threat Manager has been upgraded to provide greater visibility into AI agent identities
Additionally, the recent release introduces threat detection capabilities for Azure Files, safeguarding against ransomware and other risky changes. Future updates are set to expand agent-specific threat detection, enhancing the existing visibility framework.
Jeff Warren, CPO at Netwrix, emphasised the importance of understanding which AI agents exist within organisational systems, stating, "You can't review access for an identity you don't know you have." The latest updates bolster Netwrix's strategy to unify identity and data security, with PingCastle's assessment engine contributing to more than 200 checks in their 1Secure™ platform.
Both Netwrix PingCastle 4.0 and Netwrix Threat Manager 3.3 are currently available, offering organisations advanced tools for identity risk management. For more details, interested parties are encouraged to contact the Netwrix team.
Netwrix, a recognised pioneer in identity and data security, announces new capabilities across Netwrix PingCastle and Netwrix Threat Manager that extend identity security deeper into the Microsoft cloud, including coverage of AI agents.
Organisations are deploying AI agents faster than they can govern them. Each agent is an identity holding real permissions inside the enterprise environment, yet most exist outside any inventory, ownership, or review process.
Identities needing access
A Cloud Security Alliance survey found that fewer than a quarter of organisations have a formally adopted policy for creating or removing the identities their AI systems run on, and more than 16% don't track when a new one is created at all. The consequences are measurable: in its 2026 Data and Identity Security Report, Netwrix found a 43% breach rate among organisations where AI had significantly expanded the number of identities needing access, compared with 11% where it hadn't.
Netwrix PingCastle extends its Microsoft Entra ID coverage to 102 risk checks, extending the tool's trusted Active Directory posture assessment into the cloud identity plane. Security teams and administrators can now assess identity risk across both on-premises AD and Entra ID with the same fast, prioritised approach that has made PingCastle a community favourite.
Actionable risk insights
Netwrix Threat Manager adds new visibility into AI agent identities in Microsoft Entra ID, giving security teams an inventory of the agents operating in their environment and the access they hold.
That inventory is the missing foundation for most organisations: the Netwrix report found only 19% of organisations fully govern non-human identities such as service accounts and AI agents. Threat Manager already provides visibility and monitoring for another critical non-human identity category, service accounts, through actionable risk insights, abnormal-behavior detection, and attack context for faster triage; this release extends that coverage to AI agents.
Agent-specific threat detection
The latest Netwrix Threat Manager release also adds new threat detection for Azure Files, protecting file shares against ransomware, abnormal behaviour, and high-risk changes such as the creation of open access. Agent-specific threat detection is planned for a subsequent release, building on the visibility foundation delivered today.
The new capabilities complement Microsoft's native tooling with independent assessment and visibility across the Microsoft identity plane.
"Earlier this year, we gave organisations visibility into what AI agents can access. This release goes a layer deeper: which agents exist at all," said Jeff Warren, CPO at Netwrix. "Our research found fewer than one in five organisations fully govern non-human identities, and agents are the fastest-growing category. You can't review access for an identity you don't know you have."
Independent posture assessment
These releases advance Netwrix's strategy to unify identity and data security. PingCastle's assessment engine already powers more than 200 checks within the company's 1Secure™ platform, reflecting the same independent posture assessment approach now extended deeper into the Microsoft identity plane.
Netwrix PingCastle 4.0 and Netwrix Threat Manager 3.3 are available now. To learn more, book a meeting with the Netwrix team.