Discover Shadow AI Agents

This course shows Okta admins how to detect shadow AI agents using ISPM passive discovery and the Secure Access Monitor plugin to surface unmanaged OAuth grants.

rate limit

Code not recognized.

About this course

Shadow AI agents access sensitive data through OAuth grants and direct connectors that land outside your normal line of sight, creating unmanaged access, unpatchable vulnerabilities, and compliance gaps. This course shows Okta administrators how to bring those agents out of the shadows using Okta Identity Security Posture Management (ISPM) and the Secure Access Monitor (SAM) Chrome extension so an AI summarizer quietly running inside Salesforce, or a homegrown script granting browser-based access, no longer operates beyond your governance.

In this course, you'll learn how to:

  • Run passive discovery with ISPM direct connectors to automatically surface AI agents built on Salesforce Agentforce inside managed apps, and review owners, operational status, and granted permissions on the Discovered Agents page.
  • Deploy active discovery with the SAM plugin to capture unmanaged, browser-based OAuth grants in real time—enriched with URL, grant type, Okta User ID, resource, client, scopes, and device/browser context.
  • Triage the Browser OAuth Grants queue by snoozing, acknowledging, marking false positives, or registering a flagged grant directly as a managed identity.
  • Validate prerequisites and sync timing, including Chrome Enterprise Core enrollment, an active ISPM tenant, and super admin access, while accounting for SAM's up-to-48-hour initial sync before data appears.

About this course

Shadow AI agents access sensitive data through OAuth grants and direct connectors that land outside your normal line of sight, creating unmanaged access, unpatchable vulnerabilities, and compliance gaps. This course shows Okta administrators how to bring those agents out of the shadows using Okta Identity Security Posture Management (ISPM) and the Secure Access Monitor (SAM) Chrome extension so an AI summarizer quietly running inside Salesforce, or a homegrown script granting browser-based access, no longer operates beyond your governance.

In this course, you'll learn how to:

  • Run passive discovery with ISPM direct connectors to automatically surface AI agents built on Salesforce Agentforce inside managed apps, and review owners, operational status, and granted permissions on the Discovered Agents page.
  • Deploy active discovery with the SAM plugin to capture unmanaged, browser-based OAuth grants in real time—enriched with URL, grant type, Okta User ID, resource, client, scopes, and device/browser context.
  • Triage the Browser OAuth Grants queue by snoozing, acknowledging, marking false positives, or registering a flagged grant directly as a managed identity.
  • Validate prerequisites and sync timing, including Chrome Enterprise Core enrollment, an active ISPM tenant, and super admin access, while accounting for SAM's up-to-48-hour initial sync before data appears.