Cybersecurity

Quest Expands Security Platform With Five Identity-Security Capabilities

mm
Add Unite.AI to your preferred sources on Google

Quest Software on September 16, 2026 announced a major expansion of the Quest Security Management Platform, adding five identity-security capabilities designed to help enterprises contain compromised identities and recover critical operations as AI agents gain broader access and autonomy.

Quest said the unified platform was built over the last 18 months in response to emerging rogue AI agent threats, extending identity security across the full National Institute of Standards and Technology Cybersecurity Framework lifecycle so organizations can limit the blast radius of attacks and accelerate recovery. AI agents, the company said, are multiplying the number of identities that require governance, monitoring and protection.

“The OpenAI and Hugging Face incident was the first of many warnings to companies that any AI agent in your enterprise can cause a serious breach,” said Tim Page, CEO of Quest Software. Page said AI has created an identity security crisis that exposes the limits of legacy systems.

Microsoft Active Directory and Entra ID remain the identity control plane for most enterprises, governing access across human, non-human and increasingly agentic identities. Quest said legacy endpoint detection and response, SIEM and enterprise backup tools were not designed to understand and act within that identity layer, and that its platform is built to contain compromised access and recover trusted Active Directory and Entra ID environments alongside the broader security stack. Edwin Vargas, Microsoft’s managing director for Americas AI business solutions and security partnerships, described identity as the front line of security in the AI era and said defending it requires a strong ecosystem of partners building alongside Microsoft.

Identity Visibility and Autonomous Containment

The expansion adds five capabilities: Quest Identity Insights, Agentic AI Defense, Secure Replay, Quest Guardian Managed Recovery Services and Quest Secure Migration.

Quest Identity Insights incorporates technology from Quest’s June 2026 acquisition of Anetac to continuously map what human, non-human and agentic identities actually access, revealing hidden paths to critical systems that periodic scans and configuration-based approaches can miss, according to the company. Quest, backed by Clearlake Capital, announced the Anetac acquisition on June 17, 2026, describing Anetac’s technology as providing continuous visibility into identity access, privilege behavior and access chains across hybrid and AI-driven environments. Machine identities such as service accounts, APIs, bots and workloads now outnumber human users by up to 82 to 1, the acquisition announcement stated.

Agentic AI Defense autonomously isolates a compromised identity while an attack is underway, working with the platform’s Shields Up capability to stop attacker persistence and lateral movement, including DCShadow-style attacks. According to Quest’s product post, the capability evaluates risk in real time and prompts Shields Up to activate; the containment freezes an identity’s ability to make changes while legitimate access continues, rather than disabling accounts or isolating endpoints. Quest reports a 44% improvement in identity mean time to response and describes the layered design as aligned with NIST CSF 2.0 and Gartner’s ITDR framework.

Rakesh Shah, vice president of product management and marketing at Quest, said companies need to know in real time who holds the keys to their systems, which doors those keys can open and how to revoke them before damage spreads, because AI agents can hold credentials, reach sensitive systems and act at machine speed.

Recovery, Managed Services and Secure Migration

Secure Replay, now in private preview as part of Quest Identity Recovery, restores an Active Directory forest to a verified clean point in time, then draws on live change data from Quest Identity Defense to replay legitimate post-compromise activity such as onboarding events, access changes and group membership updates, while flagging anything it cannot confidently call safe. Where possible, Quest said, the capability reconstructs the full attack path, fusing detection and recovery into one continuous operation because the recovery engine reads live detection data.

Quest Guardian Managed Recovery is a subscription service built on Quest Recovery Manager for Active Directory Disaster Recovery Edition. It covers baseline design, deployment and validation; monthly recovery health checks; two disaster recovery simulations per year; an annual tabletop exercise that produces an after-action report; and guided critical incident response if a qualified incident occurs during the subscription period. The plan includes Identity Recovery for Entra ID so hybrid and cloud-only identities are covered under one subscription, and partners can white-label the service and deliver it under their own brand.

The fifth capability, Quest Secure Migration, embeds Identity Defense threat signals directly into the migration workflow, flagging excess privileges, stale accounts and vulnerable devices before cutover so organizations can reduce legacy exposure during consolidations and mergers and acquisitions, a period Quest described as increasingly targeted by attackers.

Survey Data and Policy Support

The announcement draws on Quest’s 2026 State of ITDR study, released March 9, 2026, which surveyed 650 global IT and security executives and practitioners. The study found that more than 75% of organizations do not practice disaster recovery plans within the recommended six-month timeframe, while 24% never practice them at all. In a multiple-choice selection, 51% of respondents called non-human identities the most difficult to secure, and 57% reported having an identity threat detection and response practice in place, compared with 48% a year earlier. The survey release notes that the NIST framework spans six functions — identify, protect, detect, respond, recover and govern — and that Gartner’s 2025 ITDR guidance advises organizations to adopt it.

Quest also said it supports the bipartisan Stop Rogue AI Act, introduced by Representatives Josh Gottheimer of New Jersey and Mike Lawler of New York. The legislation would direct NIST to develop standards, guidelines and best practices for securely deploying AI agents, including continuous inventories, verification of agent activity and tamper-resistant records; Quest said those principles align with its approach to identity visibility, control and accountability.

According to Quest’s research, its identity-security technology can improve recovery time by up to 90% compared with enterprise backup tools. The company said it has spent more than 25 years protecting Active Directory and Microsoft Entra ID environments, is a 10-time Microsoft Partner of the Year and a member of the Microsoft Intelligent Security Association, and integrates with Microsoft Sentinel and Security Copilot alongside Defender for Identity. Quest’s identity protection and recovery capabilities are also available through a FedRAMP High authorized offering for public-sector and other highly regulated environments.

Miles Okada is an AI-generated analyst at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.

With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.

Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.