News
Cybersecurity Expert: AI Raises the Stakes for Who — and What — Gets Access
A successful morning login shouldn’t settle the question of whether an employee’s actions are trustworthy for the rest of the day. As artificial intelligence makes impersonation more convincing and software agents gain the ability to act on users’ behalf, organizations need to evaluate the risk of what an identity is doing, not simply whether it supplied the right credentials.
That was a central message from technology author and former 22-time Microsoft Most Valuable Professional Brien Posey during today’s (Oct. 7) RedmondMag free online
event, Tech Spotlight | Beyond Passwords: Modern Authentication Strategies for the AI Age. Sponsored by Okta and Auth0, the event opened the Tech Spotlight series and is being made available for on-demand viewing.

“You’ve authenticated. We know proof positive who you are, but should we really trust what it is that you’re doing right this moment?”
Brien Posey, Cybersecurity Expert
Posey described a shift from treating authentication as a one-time event to evaluating identity, device health, behavior and the sensitivity of a requested action throughout a session. A familiar device and valid credentials provide useful evidence, but they don’t settle every subsequent access decision.
Match the Check to the Risk
The point is to apply additional scrutiny where it matters. Checking email is a routine activity that may need no extra challenge. Accessing payroll introduces more risk, even when the employee works in finance and has a legitimate reason to use the system.
Posey suggested that payroll access could trigger a multifactor authentication (MFA) challenge. Changing an administrator account deserves stronger verification, while transferring millions of dollars could require another person’s approval.
“So the point being that authentication should be proportional to risk,” he said.

During the audience Q&A, he made the distinction more concrete: A finance employee accessing a payroll database to process the weekly payroll is doing an expected job. The same employee attempting to download the entire database to a laptop presents a different risk, even with exactly the same permissions.
Unusual behavior doesn’t automatically establish wrongdoing. A new assignment might explain a change in activity, just as repeated failed logins could reflect a forgotten password. The purpose of examining those signals is to identify activity that deserves a closer look.
More Security Without Constant Interruptions
An audience question raised the practical obstacle: How can IT get business support for security measures that add friction? Posey challenged the assumption that making users’ lives harder demonstrates better security.
He warned that increasing friction encourages users to find workarounds. “So the better approach is to look for low friction options to improve security,” he said. In his proposed approach, ordinary work continues normally, with an additional check when a sensitive or unusual action warrants it.
He also described adjusting access to the circumstances of a session. For example, an organization might allow an employee connecting through potentially insecure airport Wi-Fi to read email and access selected documents while withholding access to sensitive databases until the employee returns to a secure network.
Give Agents Boundaries, Too
The same questions become more pressing when AI agents can read email, query databases, make purchases or deploy code. An attacker who cannot compromise an employee directly might instead target an agent with access to that employee’s resources.
“So, don’t give an AI agent access to your entire digital identity,” Posey said.
He recommended specifying which systems an agent can access, what actions it can perform, how long that access lasts and the conditions under which it operates. Short-lived credentials and narrowly scoped permissions establish boundaries around the work being delegated.

His accompanying slide also called for approval of sensitive actions, auditability and the ability to revoke access instantly. The distinction is between authentication, which establishes identity, and authorization, which determines what that identity may do.
The Rest of the Session
Posey also discussed AI-assisted phishing, voice cloning and adaptive social engineering, along with passkeys and the role of biometrics within a broader authentication system. The full presentation and Q&A are included in the webcast replay.
The sponsor session, “From Friction to Conversion: How to Optimize Identity for Growth,” featured Auth0 staff product marketing managers Bradford Pierce and Saad Rahman, along with senior solutions specialist Alex Kemenov. They discussed how login and enrollment requirements affect customer transactions and why consistent identity across applications and brands matters.
Kemenov demonstrated embedded login flows that let a guest complete onboarding, enroll a passkey and return with a faster sign-in experience. The demonstration also showed customer information being filled in during checkout. The discussion connected stronger verification for sensitive actions with reducing interruptions during ordinary use — a customer-facing counterpart to Posey’s enterprise guidance. Replay viewers can watch the application flows that a slide-based article cannot fully reproduce.
And More
While replays are convenient and informative — especially up-to-date sessions that just concluded — attending live events offers advantages, including the ability to ask specific implementation questions and receive guidance in real time. With that in mind, here are upcoming online webcasts and summits from Virtualization & Cloud Review, along with webcasts and virtual summits from RedmondMag:
About the Author
David Ramel is an editor and writer at Converge 360.
