Okta, Inc. (OKTA) Earnings Call Transcript & Summary

October 16, 2024

NASDAQ US Information Technology IT Services conference_presentation 286 min

Earnings Call Speaker Segments

Unknown Attendee

attendee
#1

This presentation contains forward-looking statements. We reserve the right to change the information in this presentation. More information can be found in our security filings. [Presentation]

Unknown Attendee

attendee
#2

Please welcome Okta's CEO and Co-Founder Todd McKinnon.

Todd McKinnon

executive
#3

Hello, and welcome to Oktane. We are thrilled to have you here. Everyone online, my wife is watching online. Hi, Roxanne, and everyone here in this jampacked room. My father is here. Welcome, George. We are going to tell you a story about a company that has gone through a major transformation. And this story starts with identity. Identity is who you are. It makes you, you. It's your reflection in the world, both personally and professionally. It's the entry point to the digital world. Determines what you can access and when you can access it. It's something that can make organizations more productive. It can make every single interaction with technology faster, smarter, and more secure. But there's something more important. There's something more important. While identity can be a powerful force for good, identity is also under attack. Over 80% of security breaches involve some kind of compromised identity, whether it's the initial compromise or how the threat moves laterally. So the stakes have never been higher for identity. And because identity is the foundation of technology, it's become the key to security. To get security right, you have to get identity right. A simple way to sum it up, identity is security. And the threat environment that we are all living in raises the bar for what an identity system has to be. It has to be agile and respond to threats. It has to be deeply integrated into every part of your ecosystem. It has to be independent and neutral, not part of some monolithic stack that's trying to lock you into one ecosystem. Now this is obvious to many of us today, but it wasn't always the case. If we rewind the clock back to 2009, when starting Okta, the world was in the early days of adopting cloud computing. And Okta's focus, our focus was on IT enablement. We were working hard to build a platform and a set of capabilities that would help companies adopt the cloud. Today, identity is still the entry point to the digital world, but it's become so much more than that. And with that change, so have the expectations of Okta changed. So we have a huge target on our back. We have a huge target on our back, and we are responding. Every month, Okta blocks over 3 billion identity attacks. These are credential stuffing, bot attacks on the Internet, broad-based attacks and very focused attacks. So this means that everything has to change. We aren't just powering the cloud. We are securing it, too. And this has resulted in a totally new risk model for Okta. We had to start treating every risk, no matter how small as something that would be found and would be exploited. We had to evolve how we build our products, how we protect our corporate infrastructure and how we manage risk. And maybe most importantly, we had to change our mindset. We had always thought of Okta as an identity company. And while that's still true, in a world where identity is security, Okta is a security company. And since last Oktane, we have had an all hands on deck approach to becoming one of the most secure companies in the world. Now we got a lot done in this period of time. And we have emerged a much stronger company because of it with a very clear vision and sense of purpose for our role in technology. This focus is captured in the Okta Secure Identity Commitment. The Okta Secure Identity Commitment is our long-term commitment to lead the industry in the fight against identity-based attacks. And it has 4 key focus areas. The first is building market-leading identity products that are secured by default; hardening our corporate infrastructure; championing customer best practices; and finally, elevated the entire industry to be more protected from attacks. Now since launching the Okta Secure Identity Commitment back in February, we have made a tremendous amount of progress. On the Workforce Identity Cloud, we've launched Identity Security Posture Management, Identity Threat Protection with Okta AI and Govern Okta admin roles. Customer Identity Cloud has seen the launch of the fourth generation of our bot detection technology, along with Fine Grained Authorization and Highly Regulated Identity. In the last year, we have invested over 1 million hours directly focused on security, 1 million hours. If I would have done this myself, it would have taken 110 years. Luckily, I didn't have to do it myself. I have an awesome team. Now it's a lot of progress on the screen, but it's just scratching the surface. The list goes on and on. This is a long-term commitment, and we will not stop until there are no more identity-based attacks, no more. It starts with helping ensure that customers are best protected. And that's why we created the secure identity assessment. Secure identity assessment builds on what we talked about last year with our Expert Assist offering. Expert Assist, as many of you know, since you've utilized it is where our experts make sure that your Okta installation is set up to the highest secure configuration and to make sure everything is locked down and up to your posture. Now secure identity assessment takes us a step further by doing the same thing, but not just for Okta, but for your entire ecosystem. See, our team, we've worked with some of the most secure organizations in the world, and we've learned a lot. And we want to share those best practices with you. And the best thing about it is that as you're identity security posture improves over time, we can reassess it and make sure you attain the level you want and you require and you're maintaining that level even as your technology, infrastructure and ecosystem evolves. Helping protect customers from attacks is a very important priority. But we also want to protect the broader communities that we all live and we all work in. In support of this goal, earlier this year, we launched -- or we announced a philanthropic commitment of $50 million to build a more secure world. And this future, as we all know, talent is critical. We have to have the right talent. Yet today, 4 million cyber jobs remain unfilled globally. So this is an issue for all of us. And the entire industry needs to move faster, building up and training the next generation of cyber talent. I want to spotlight an amazing organization that they're working hard to reshape the technology workforce of tomorrow. CodePath, it's an amazing organization and an amazing mission. They're all about meeting the needs of underrepresented computer science students, seeking careers in technology. Matching them with employers like all of us seeking strong, diverse job-ready talent. CodePath, they're on this mission to reprogram higher education, and we're taking actions to help them. We're partnering up. And along with we're going to build an open-source cybersecurity lab that will reach 3,000 students a year and ensure they're prepared to take on these key roles in the cybersecurity industry. We are so proud of this. Sometimes, these people that are early in their career just need a nudge, just need a little extra help, and they're off on their way, building a great career, helping the world in this important area. We couldn't be happier. So nice job. Nice job CodePath. So now learning and growth, continuous learning and growth are very, very important to us at Okta. And our transformation and our increased focus on security has taught us a lot. Becoming one of the world's most secure companies has required that we harden our own corporate infrastructure. And this means, of course, using our own products. It should be easy, right? We're a security company using our own products. And this was so critical, so critical. I got personally involved working directly with the product team, attending the daily meetings and adding my input. You can ask them what they think of this, but very important. And I learned some incredibly interesting things. Like, for example, do you know how many applications Okta has inside of our corporate infrastructure? Throw out some guesses. 5, someone said 5. No we have more than that. It's over 1,300, 1,300. Now many of you in this room, you have incredibly complex infrastructures at your companies. So this may not phase you, but I was surprised. I was surprised. And so what did we do? It was a tall task, but we do what Okta always does. We rolled up our sleeves and we got to work. Now getting a complete list of all these identities and all these applications, making sure we had end-to-end phishing resistant authentication for all of these things from the second the account was created or employee was onboarded. All through the resets and the job changes, et cetera, until when they're offboarded, doing this for machine accounts and human accounts, making sure it's all restricted to the access from the corporate VPN, making sure that it's only from allowed list of IP addresses, making sure that the privileged accounts are locked down, making sure the secrets are vaulted and rotated, making sure we have identity governance workflow across the whole thing. This was all very hard, very hard. Now, here's the other thing about it. It's way harder than it should be. And if it is hard for us, imagine what it's like for an organization where identity and security is not their main business. And why is this so hard? Why is this so hard? Well it's not -- we have great people, we have great products. But the reason it's so hard is because all the applications and all the technology is different. It's all different. They don't integrate well. And this yet led us to a simple but a profound realization to solve the identity security challenge that is afflicting the world, we need massive standardization, massive standardization. There's no identity security standard that ensures visibility and interoperability across all of technologies. Sure, we have SAML and SCIM that help. But as our own experience shows us, as our own experience shows us the industry, its far from where it needs to be. It isn't easy for a resource or a workload or an API or any other enterprise technology to make itself governable, discoverable, support SSO, support provisioning and continuous authentication. Now if we solve this, we are on our way to solving the issue behind 80% of all cyber breaches. And it doesn't matter if you have the best network security. It doesn't matter if you have the best endpoint security or cloud security, these things are necessary but not sufficient. If you don't have complete visibility into every touch point in your ecosystem, if you aren't listening to all the risk signals and able to take concrete action response, you are vulnerable and you are exposed. So this lack of standardization, it's the single biggest issue and the single biggest barrier to cybersecurity today. It's the problem of our generation. So the time is now to fundamentally reevaluate how we think about identity security. We need to move to a world where every app, every device, every workload, they all speak a common language. We need a way to standardize identity security. Think about some of the other standards that have impacted our world, like TCP/IP. If I have to explain to you what that is, you're at the wrong show or even something as simple as a screw. Now screws, they aren't just a story about standardization. They also represent the power of integration. Henry Phillips, yes, there was a guy named Henry Phillips. He didn't just come up with a strong x-shaped design that's made screws ubiquitous today. He also knew that for screws to have a big impact, he needed to license the technology broadly. So the importance of a screw can't be underestimated. It makes the modern where possible, the growth of the automobile industry, the space race and every household project, my dad and I have done together, possible with the crew. So our goal is to standardize identity security across the industry. And in doing this, we will help foster an ecosystem that is seamless and efficient to build enterprise technology and use it in an environment that will be secured by default. And we want this to be open so everyone can benefit. Now let's see what the scope of this would look like. You recognize in this picture on the right, something that looks like your corporate infrastructure. It is complex, cloud apps on-premise applications, AI agents. Now with the right kind of standardization, you'll have complete control over every part of this ecosystem. Identity does familiar things like SSO and MFA but also more advanced things like life cycle management and entitlements. It listens to risk signals and can take actions like Universal Logout. It can manage your security identity posture across your entire enterprise. Some of these areas, they have standards like OpenID Connect for single sign-on or SCIM for provisioning. But even there, it's not clear how those standards should interact with other parts of the picture. How do you make sure you bind an SSO session to a device, unclear. And then in some areas, there's no standard at all, like there's no standard for Universal Logout. We want this all to be simple, secure and open to everyone. So our solution is a new standard that covers this entire picture. The standard is called Interoperability Profile for Secure Identity in the Enterprise or IPSIE. Yes. So if you're still wondering if you're at the right conference, you know you are because we are an identity company, and we have never met an acronym we did not like. We've led the formation of a working group with inside the OpenID Foundation let's say aim of defining the standard, creating it and working with the whole ecosystem to evolve it into a unified identity security standard to solve all of these challenges. Now this is a key part. This is open and involves everyone, other identity providers, the biggest to the smallest, other technology companies. We're going broad and wide with this because it only works if it covers everything. An identity security standard that covers a couple of things, not super valuable. Today, the identity industry can't integrate deeply enough into technology and the people that are building technology, they don't have a simple and consistent way to allow these connections to happen. They're all reinventing the wheel. And IPSIE is meant to codify this connection. And in doing so, it will dramatically improve identity security. Imagine you're building technology. It will give you a clear identity security blueprint that will make your solution far more secure. And organizations that standardize on IPSIE-compliant technology they'll get complete visibility into their identity environment and the threat surface, and they can provide access to what we all want, the right applications at the right time and take real-time actions in response to threats. Now this part is important, all at a fraction of the time and cost it takes today because it's too hard, it's too expensive. We need to solve these problems as an industry and get back to the main businesses we're all in. So Okta is committed to this world and leading this world in the fight against identity-based attacks. This standard is the most transformative way we can move the entire industry to a more secure place. Now think about our own example of hardening our corporate infrastructure. In a world where each one of those 1,300 applications have been built to be IPSIE compliant, we would have been able to move much more quickly in securing our own and increasing our own security posture. We would have had faster, complete end-to-end visibility into every aspect of our ecosystem, every nook and cranny, every element of it. We want this to be available to everyone, more signal sharing, more SCIM, Universal Logout everywhere, all requiring fewer calories, fewer calories. Now we're turning the show into a diet seminar, has to be cheaper, has to be easier. We all know in security complexity kills makes everything brittle. We can solve these challenges. So in some ways, this is a big deal, huge and revolutionary. But in other ways, it's a continuation what we've done before. When we -- we've been kickstarting the adoption of standards like OpenID Connect and SAML and WS-Fed since Okta's earliest days. When we got started with SAML, it wasn't widely adopted. So we built the first version of the Okta Integration Network by hard coding, screen scraping to every application that didn't support SAML. And as more applications supported it, we updated the integrations, the ecosystem -- upgraded the integrations and authentications happened quickly and easily and seamlessly as a result. So we are no stranger to standards and how standards can move the entire industry. We've done this before, and we're doing it again. Launching IPSIE and starting the standardization process is just the beginning. We aren't waiting around for this. And just like in the early days, we're pouring resources into solving real customer problems today. And that starts with secure identity integrations. We're meeting you where you are today by building 125 new secure identity integrations across some of the biggest names in enterprise technology, Google, Office 365, Atlassian, Slack. Now the idea here is to make these integrations behave exactly like everything will behave when everything is IPSIE-compliant. So imagine this, think about this as a glimpse into the IPSIE future. Now this wasn't easy. We spent a lot of time taking an inventory and building all the integrations into the most critical applications manually doing this work. And in the future, as IPSIE is adopted everywhere, all of this will be easier and easier and faster and cheaper, but we wanted you to get the results sooner. So this is all very important. But another key to making this move forward and be effective broadly is that as many applications as possible, as quickly as possible, need to support Universal Logout. Now the Customer Identity Cloud is the identity layer for thousands of applications out there. So if we added support to the Customer Identity Cloud for Universal Logout, it would be supported by these thousands of applications immediately, and that's exactly what we've done, exactly what we've done. So this means as the IPSIE standard evolves, thousands of applications out there that use the Customer Identity Cloud all are well on their way to being compliant. Now Universal Logout is just to start. Over time, we'll add more capabilities to spur adoption even further. So this is a virtuous cycle. We are providing real value today with secure SaaS integrations. This makes customers more secure, so they'll start to demand it of all of their technology. We're working with everyone in the ecosystem to codify IPSIE. We're adding elements of IPSIE to the Customer Identity Cloud, which will lead to more IPSIE compliant technology, more secure SaaS integrations and most importantly, more secure customers. You can see we're putting all the pieces in place to eliminate identity-based attacks. And let's be clear, we will not stop until we get there. And what an amazing accomplishment that will be, what, a better future. So doing this is an important step in our overall vision, and that is to free everyone to safely use any technology. Are you excited about this? Hopefully, yes. I'm glad. I'm glad because like a lot of things in life, there's a catch. The catch is we're going to need your help. We're going to need your help. First of all, you have to believe this is possible and get aligned that we can build a better future. For those of you that saw the keynote, the intro keynote yesterday with Alex, how do you do something impossible? First thing you do is you tell yourself, it's not impossible. It's just really hard. And then you break it down and you do it. Second is dig in, understand the standard and give us feedback, collaborate on us. Now if you're building technology, make sure it adheres to these IPSIE principles. We're going to make that really easy, whether it's adding capabilities to the Customer Identity Cloud, publishing tools and documentation, make it all very clear and transparent, get everyone's input, make it open and accessible to all. And finally, if you're buying technology, make sure the vendors are IPSIE-compliant or headed that way. They need to be on board with us, all of us. And now we know that introducing new standards is hard. And to get them bootstrapped, they have to be open, and we've talked about that. It has to be easy and simple for every technology company, no matter how big or how small, to adopt them. Now the good news is we already have some of the biggest in the business on board to help us.

Unknown Attendee

attendee
#4

Thank you for the warm welcome, Todd and hello Oktane. I love that name, by the way. Unfortunately, I couldn't attend in-person, but I'm thrilled to represent Google and our partnership with Okta today. As many of you know, security and user experience drive all of our product decisions here at Google, and we see Okta as a class-leading identity provider with the exact same goal. Now like Okta, we believe in ecosystems over monoliths and an independence and neutrality, so we can strive to provide customers with the best available choice. Now throughout the journey, Google and Okta have done a lot together and have delivered a lot of value to our customers. We've added key identity security features directly into Chrome for our enterprise customers globally. We have extended that for popular desktops and Mobile OASIS so that we can embed threat detection and posture management, again, directly into Android and Chrome OS. And now with Google Workspace, a partnership that we launched last year, we are seeing great traction with prospects and customers. Now customers see security and user benefits of having communication collaboration apps, such as Gmail, drive, docs and meet that people know, love effortlessly and safely accessible with the leading identity provider Okta. And I'm really excited to see the latest ongoing effort with Google Cloud and our security offerings such as Google Security Operations so that we can fundamentally bolster security across the board for customers wherever they are. And so as industry leaders, we now have to set the bar and keep the bar high. And like Okta, Google is a huge proponent of identity standards. And to get security right, we all know we need to get identity right. Vendors and app developers cannot let their silos and proprietary approaches get in the way of securing our shared customers. So we all need to do more to ensure security before at and after the logging process so that right people can access the right resources at the right time. And at Google, our DNA has allowed us to lead in these areas over the last few decades. But overall, the industry needs this. And I think more importantly, the audience here, our customers need this and should be demanding this. So we look forward to our further collaboration and alignment with the new OpenID working group, which has already done some amazing work to get. So I'm really excited about the journey ahead. Thank you again for having me at your event. Enjoy the rest of the show, and back you, Todd.

Todd McKinnon

executive
#5

It's great hearing from Sunil, and we love working with Google. When I talk to companies, software companies and technology companies, large and small about this mission of eliminating identity-based attacks. The conversation is never about the why. The why is incredibly clear. It's always about the how, how do we do this. So IPSIE is a collaborative effort across the whole industry to clarify the how and move forward rapidly toward solving these problems. So we've heard from one of the largest companies in the world from their perspective. Now next, we're very lucky to have someone to have a conversation with a customer of Okta, who is also a software company. So it's an interesting perspective into all these ideas we're talking about. So please welcome the Chief Information Officer of Workday, Rani Johnson.

Rani Johnson

attendee
#6

Sorry, I didn't run out here.

Todd McKinnon

executive
#7

No, worries, yes. Well, I got a little out of breath. So thanks for joining us. how does Workday think about application security? And how does this fit into the way you think about Workday and its opportunities and its internal infrastructure in?

Rani Johnson

attendee
#8

Well, at Workday, we are simply obsessed with creating delightful user experiences for both our customers and our employees. And we understand that securing those user experiences are frankly, table stakes. We believe that security should be intuitive, slightly invisible and seamlessly integrated with how users interact with our applications. And this is why we're constantly evaluating security capabilities like identity governance, passwordless and privileged access management. We believe that security and user experience have to go hand-in-hand. And if security is cumbersome or in any way intrusive, people will find ways to circumvent it. Not you good people in IT and security, but everybody else. And this is why we're striving to make security so user-friendly that it becomes second nature. At Workday, we managed the sensitive data for over 10,000 customers and millions of workers. And security has to be at the foundation of trust in our platform. So security is a nonnegotiable.

Todd McKinnon

executive
#9

Yes. Talk about someone that understands internal security and hardened corporate infrastructure. So the internal governance rollout, pretty easy. I like your term slightly invisible.

Rani Johnson

attendee
#10

Slightly. Got to know it's there.

Todd McKinnon

executive
#11

I heard Rani was telling backstage that their rollout of identity governance is going very well. So I'm excited about that. We don't want to comment until it's completely done. I understand.

Rani Johnson

attendee
#12

Feeling good about it, though, Todd.

Todd McKinnon

executive
#13

What do you -- I'm sure in technology world, you've heard about standardization and some standards work and take off. What do you think about this idea of trying to standardize identity security?

Rani Johnson

attendee
#14

Well, as an IT professional, we know standardization is the right answer. But as a long-time customer, we are constantly impressed by Okta's ability to manage identity at scale. And so we're internally focusing our use of Okta to encompass more identity profiles. And so for us, we're trying to get off, frankly, active directory and security group.

Todd McKinnon

executive
#15

Sorry about that. If we would worked harder, it would have happened already.

Rani Johnson

attendee
#16

It's a lot of work that we're on the path. And we're focusing on automating onboarding and offboarding. You talked about that a little bit earlier for us. It's provisioning access just in time. We have also leveraged some insights from Okta to actually do license reclamations and we're also not over licensing our workers. And then most importantly, we're streamlining visibility, making sure that we've got identity analytics. And as you mentioned, I'm super proud of this. We only rolled out OIG recently around our user access reviews. But the folks in Workday security and IT teams will tell you, when we did that just a month ago, we included for the first time, applications that were under [ SOCs ] controls, so not just those with the security objective, but those with a compliance objective. And so this is around like literally like our sales force environments and our Workday environments and rolling out those UARs, we did that with significantly less manual intervention, less headache on our side, but we did, we were successful, and I'm going to just tell the truth on this too. We automated the escalation of frankly, telling your boss by a slack that you hadn't done your UAR, and we did the threat of, frankly, the reclamation, and we actually had significantly more success with much less, much less intervention...

Todd McKinnon

executive
#17

That's amazing, I love it, yes. Yes. I'm laughing, I'm smiling up here because I'm smiling up here, when I listen to your talk because I'm just thinking of selling technology to another technology company, a company that has great products and great user experience. The bar is always very high. So I'm glad to hear that it's going well. What about for customers? What do you think this could cut the customers of Workday? Because you're the CIO of Workday, but obviously, Workday has a very strong presence in the market, delivering HR and financial management and the whole platform of products. What do you think this means for customers?

Rani Johnson

attendee
#18

Well standardization, just frankly, it simplifies administration, but more importantly, it enhances security for our customers. It enables the authoritative source of identity for authentication and helps us to achieve and enforce our security and compliance objectives. We have been advocating for our customers' use of MFA for a really long time now. We are moving to the stage of enforcing MFA across our customer environments. We know that our customers should have stronger protection for employee data. It's our responsibility at Workday to ensure that only authorized individuals access this important and sensitive data and our reputation depends on it.

Todd McKinnon

executive
#19

Yes. It's kind of like I was talking earlier about Expert Assist. If it's our -- I mean, we think about it as our fault, if Okta is not set up, right? I mean technically, customer has to help us, but we don't want to say like, oh, it's your problem. We want to help them.

Rani Johnson

attendee
#20

Exactly.

Todd McKinnon

executive
#21

So looking forward, when we're back here next year, we're already booking you for next year, you're so good up here. What are we going to be talking about? What's next for Identity Security at Workday?

Rani Johnson

attendee
#22

So first of all, I'm a huge introvert and a big old nerd, so this is...

Todd McKinnon

executive
#23

Yes, exactly. You're doing great.

Rani Johnson

attendee
#24

I got coerced.

Todd McKinnon

executive
#25

You're doing great.

Rani Johnson

attendee
#26

I appreciate it.

Todd McKinnon

executive
#27

You can't see anyone out there anyways. The lights are too bright. There's only a few rows deep.

Rani Johnson

attendee
#28

It helps. It helps. So we're focused on enhancing our identity strategy in a few key areas. The first one is passwordless. We obviously want to make a better user experience and make security kind of seamless for our employees. But the more interesting one for us is really contextual access. We're moving beyond basic role-based access control to create more dynamic context aware approach. Considering factors like location, your device MAC address or, frankly, even the time of data to make sure that the access is appropriate when you're trying to gain it. You can't go to a user conference without saying AI, so check. We're also...

Todd McKinnon

executive
#29

This is a record. We're like 35 minutes in, I said AI agent. So, yes.

Rani Johnson

attendee
#30

If you're taking a shot every time you say AI, you'll be drunk by the end of the day. So we're deploying AI-powered identity analytics to proactively identify and mitigate threats and frankly, help stay aware of potential vulnerabilities. We're aiming to create truly frictionless, secure identity experiences that empower the employee and strengthen our overall security posture. And for what's next for Workday? We are continuing to define the future of work. And when it comes to AI, we are not new to this at Workday. We have been true to this for over a decade. Our next generation of AI, we're calling Workday Illuminate is taking us beyond task automation and to true transformation. Imagine that our AI will act as like a personal coach. It's accelerating the employees' performance. Freeing workers to focus on meaningful, to impactful tasks and reducing the kind of the burden of kind of redundant work, really elevating human potential. We're aiming to move business forever forward, and we're excited to partner with Okta on defining and shaping the future of Workday.

Todd McKinnon

executive
#31

Yes. We're thrilled to have you. Thank you so much. The perspective is super valuable. Rani Johnson, everyone.

Rani Johnson

attendee
#32

Thank you, Todd.

Todd McKinnon

executive
#33

The issue of identity security standardization, it's a real problem, a problem impacting all of us today. Now let's learn about a customer that's taking this problem and turning it into opportunity. [Presentation]

Todd McKinnon

executive
#34

That's right. Cigna, Fortune 15, 15 company using Okta to innovate across health care. To show you this in more detail please welcome 2 leaders from Okta's product marketing team, Harish Peri and Jen Vaccaro.

Harish Peri

executive
#35

So Todd was sprinting. I figured I would hop and skip, but that didn't work out. How are we doing Oktane? Are we having fun yet? There we go. That's what I'm talking about. So as you saw in that video about our amazing customer Cigna, Open Enrollment is a critical time for them. They have millions and millions of customers accessing their system to conduct very sensitive transactions. And the security risk on that company is incredibly high. So for the next few minutes, we are going to take you on a journey. We're going to show you a demo of how Okta secures every part of Cigna, every app, every interaction, every touch point, everything. I'm going to show this to you from 4 perspectives. The first is that of an IT administrator. The second is that of a customer service rep, an employee. The third is a developer working on the myCigna application and the fourth is a health care customer actually using that app during Open Enrollment. So let's get going. Let's start with the IT admin. Cigna's admins have to manage thousands and thousands of applications, every single one of which has its own governance, its own entitlements, its own access policies. It's very complex. It's a lot of work for these admins. Let's take a look at their ecosystem. What's already great about this is that many of their apps already support the secure identity integrations that you heard Todd talk about, which means, of course, they're secure, but it also gives the admins visibility into what's going on. You have apps like Zscaler that support risk signal sharing and you have apps like Salesforce that support SSO, MFA, entitlements, life cycle management, signal sharing and Universal Logout, pretty powerful stuff. But beyond just making things secure these integrations also let their admins do their own jobs better and faster so they can focus their efforts on supporting Cigna during Open Enrollment. That's what counts. But that's only one part of this. To further protect Cigna, these integrations also give their admins unprecedented visibility into identity risks across their ecosystem. This is Identity Security Posture Management, or ISPM. This is a phenomenal capability that shows their admins identity risks from across their entire enterprise, risks like unused accounts, admin sprawl, bad password hygiene, just to name a few. But it gets better. The admins can click into a specific kind of risk and actually see the users that have that risk. But wait, it gets better. They can actually click into a specific user, and this is my favorite part. This is my favorite part. I'm biased, but is my favorite part. This shows the admins the access graph at a user level, what that user has access to and how they have access to it, very, very powerful stuff. But where it gets really, really good is the admins can actually take a remediation action directly from ISPM. This takes them to Governance Analyzer with Okta AI. What Governance Analyzer does is bring together vast amounts of data from the ecosystem to create a highly targeted recommendation of what to do with a specific entitlement problem. In this case, it's recommending that we revoke that users access. I want to remind everyone what we just saw. We saw a macro level view of identity and security and a micro-targeted, surgical recommendation of how to fix a specific user problem. That is identity security in one place, extremely powerful stuff. That's the admin side of things. Thank you. Yes, yes, yes. That's what I'm talking about. If you know you know, now that's the admin side. Now when we keep this journey moving. Let's see what this looks like for an employee who's onboarding themselves into Cigna to get productive securely on day 1. And for that, I'm going to pass it off to my friend, Jen.

Jen Vaccaro

executive
#36

Hi, everyone. It's my first day as a customer service representative, hired to help during Open Enrollment period. And because this is such a busy time for Cigna, it's imperative that I securely get access to all my apps so I can be productive on day 1. With this welcome e-mail, I can begin activating my account without waiting for IT approvals. Instead, I can use a seamless self-onboarding flow, using secure ID proofing. Now if we proceed here, it's already kicking off the ID verification process using [Clear], which is possible because of [Clear's] deep integrations with Okta. And as I proceed, I already have a [Clear] account. So all I have to do is type in some basic information like entering a code here and taking a selfie for face ID. Now let's hope they caught my good side. Now as we proceed, I can log into the Okta dashboard, where I already have access to all my essential applications to be productive day 1. But that's not all. I can request access to additional applications and privileged resources on behalf of myself and others, simply by inputting some basic information here, and we'll be able to get that up and running pretty quickly. Now what we've just seen here is the future of onboarding, and it's here today. From my initial onboarding flow to birthright access, to entitlements and Universal Login that the IT admins configured, Okta can help Cigna ensure that the right user gets the right access at the right time, fast and easy. Back to you, Harish.

Harish Peri

executive
#37

Thank you so much, Jen. That was pretty cool. We saw an administrator securing their applications, and we saw an employee getting onboarded quickly. Let's keep this journey moving. Let's see what it's like for an actual developer securing the myCigna app. Now Cigna's developers during Open Enrollment are dealing with one of the most notorious kind of risks, bots. Bots are on the rise and they are on the hunt for sensitive data exactly like you would see in open enrollment. Well, with Auth0, Cigna's developer can embed bot detection directly into the myCigna app without having to write a lot of code, it's highly configurable and it uses a tremendous amount of collective intelligence to help determine what's a bot and what's not. So that's bot detection. But there's one more thing. Our developer here can also ensure that the users of the Cigna app actually have the right authorization to access the right kind of data. And this is where Fine Grained Authorization or FGA comes in. They can very easily model complex relationships like beneficiary independent, which is key to open enrollment and again, ensure that only the right users access the right kind of data. And just like that, our developer was able to secure their app against bots and also make sure that user access data is controlled in the right way. Now let's close out this journey. Let's see what it's like for an actual health care customer accessing the myCigna application during Open Enrollment. Let's see what their experience is like. For that, back to you, Jen.

Jen Vaccaro

executive
#38

Now I need to log in to finish my Open Enrollment. And as I do so, Auth0 is checking for bots in real time to make sure that my account doesn't get breached and that I am indeed a human being. And it looks like I have a new message. Let's see what it says. It's the Cigna AI chatbot, and it's asking if I want to update the address of one of my dependents because it noticed an address change in the app that we use to manage prescriptions. This is possible because I have previously authorized this chatbot to take this type of action on my behalf. And under the covers, this chatbot is powered by Auth for GenAI, which helped secure the identity of GenAI applications. And I'm able to view all this information of my dependent because of the Fine Grained Authorization model, we just saw the developer configure. And since it's a bot acting on my behalf, we can use async authentication to verify with a human. Now I'll go ahead and approve this flow, and I'll use my phone for that last verification here. I'll approve that. and use face ID. That was pretty easy. Now back to you, Harish.

Harish Peri

executive
#39

Thank you so much, Jen. We covered a lot. So let's recap. We saw how administrators and developers can embed security deeply into every part of Cigna's ecosystem. And we saw how customers and employees can benefit from our security without sacrificing user experience. When you step back and when you bring all of this together, this is what it really means to free everyone to safely use any technology. Thank you. Back to you, Todd.

Todd McKinnon

executive
#40

All right. Thanks, Harish. Thanks, Jen. It's great to see the power of Okta in action at Cigna. Cigna team here? Thank you. Thank you very much for being such a great partner. Now you can hear about all of these incredible products throughout our keynotes today. Our ability to build these innovative products is deeply dependent on our interactions and our feedback from you. And this has been one of Okta's core strength and value since our earliest days. In fact, when we first got into the customer identity business, it was because customers were asking us to use our workforce identity products for customer use cases. So we're always listening and adjusting and trying to make things better. Since 2022, after the acquisition of Auth0, we focused our customer identity innovation there. And many of you, including Workday and Cigna, use customer identity solution. And as you know, we're committed to supporting and maintaining this forever. In fact, it shares 80% of the code with the Workforce Identity Cloud. So you've seen a steady stream of updates just by the fact that it's on the same platform. We've also added critical enhancements based on customer demand as well. So in the past 2 years, I've had many, many conversations with customers about their visions and their requirements for innovation and customer identity. And it's been clear that they were pretty worried about having to migrate to Auth0 or the cost and complexity of that. So after hearing this feedback, I'm very happy to share that we are accelerating investment in the customer identity solution. And that means -- what does that mean? That means more innovation and more new capabilities. It means we're going to be sharing a road map with regular updates so you can plan accordingly. In fact, the first version of this or the first discussion of this will be in the Customer Identity Solution road map session later tomorrow afternoon. So both Customer Identity Solution and Auth0 are critical, critical parts of our future, and each will have their own specific road map with regular updates so you can have a very clear idea of where they're going and you can plan accordingly. We believe that customer identity is very broad and diverse, and we want you to be able to choose the right solution for you, and we're here to support you because everything we do comes down to making you successful from Wyndham to JetBlue to MLS to Siemens, to Zoom, to Mars to over 19,300 customers around the world, they rely on Okta every day to secure access for their workforce and their customers. We don't take that lightly. We're honored to serve you and working hard to do it. So wherever your business is headed, Okta makes that possible. And this shows up in our numbers. We're the largest independent and neutral identity company, which just blows me away every time I say it. Our customer base covers over 40% of the Global 2000 and 60% of the Fortune 500. We have the industry's broadest and deepest set of integrations with the Okta Integration Network with over 7,000. And you can see today, we're enhancing and innovating and driving the industry to make that even better. Every month, we have 1 billion unique users across our 2 clouds. Now let's hear from the leaders of those 2 clouds. First up, to talk more about the Unified Security Solution for the Workforce Identity Cloud is the Chief Product Officer of the Workforce Identity Cloud and also the best dressed man at Okta 7 years in a row, Arnab Bose.

Arnab Bose

executive
#41

Thank you, Todd. It's so inspirational to hear the success stories of customers like Cigna and Workday, businesses which are making identity the backbone of their security strategy. Every company must adopt a similar strategy because today, identity is the security perimeter. When engineering teams spin up new AI models, they're looking to unlock business outcomes like accelerating clinical trials for a new vaccine or automating customer engagements via support agents. But us, in this room, what we see is machine identity sprawling, over permissioning and chances for lateral movement. And when an employee gets a voice mail from an executive asking for help, they think they're earning browny points.

Todd McKinnon

executive
#42

Hey, it's Todd. I left my phone in the car while going to this customer lunch, and I can't check my e-mail. One of our investors is forwarding you a document, I need ASAP. Can you download it and text some screenshots to this number? I'll owe you big time.

Arnab Bose

executive
#43

Now I've worked for Todd for over 5 years, and I know he doesn't need slides to get a customer meeting right, but that deepfake was pretty realistic, right. What we are seeing is bad actors getting savvier and savvier and securing our workforce getting harder and harder every day. We see more attacks than we did just a year ago, 180% more, in fact. And it's taking organizations over 290 days to recognize and contain a breach. That is why we need every layer of the tech stack to support an open standard like IPSIE. Imagine a world where your whole tech ecosystem conforms to the IPSIE standard. It will provide the strongest level of identity security before, during and after authentication. Before authentication, you can discover and remediate risky identity misconfigurations. During authentication, you can achieve outcomes like end-to-end phishing resistance, device found sessions and getting to 0 standing privileges for both humans and nonhuman accounts. And after authentication, you'll be able to continuously listen for risk signals across your entire enterprise and terminate sessions with Universal Logout. The future of identity security is powered by the IPSIE standard. And the good news is we are well on our way to achieving this vision today. Let's take a closer look at how we secure each of these 3 phases and how we are innovating to give you even more control. Before authentication, customers need to discover identity misconfigurations like partially offboarded users or inconsistent MFA. You saw this in the demo we showcased before. ISPM showing you that user access graph, where even though you might have that application behind SSO, that same user has direct access to the application through other means. ISPM integrates to major cloud vendors, IdPs and more to uncover risks fast. In this phase, you also need to discover and remediate excessive standing privileges and take actions to rightsize these entitlements. However, managers and approvers don't have all of the risk context. They're being asked to approve these access requests without all of the data to make the right decision at the right time. This is a problem you'll be able to address with Governance Analyzer with Okta AI. Customers will be able to leverage the full power of Okta's platform from device posture assessments to relationship data and past governance decisions as well to get real-time recommendations to get authorization right. And as apps adopt the IPSIE standard, Governance Analyzer will get even better because it'll get plugged in to every single application in your tech stack. Now our end-to-end use cases don't just stop with applications. You might think that setting up a single sign-on for an application is what you need to secure access to it. But every SaaS application or cloud-based product also has break glass accounts or admin accounts to set up the config in the first place. If we don't pay attention, these accounts can easily go unprotected and be a way to bypass your security checks. Meet Secure SaaS Service Accounts. Now you can discover, vault, automatically rotate and manage these service accounts with Okta. And as -- yes, there you go. It fired up. And again, as the IPSIE protocol becomes more widely adopted, discovering SaaS Service Accounts will be easier than ever. And again, your whole tech stack, every application in your tech stack will start supporting this awesome capability. Now let's take a look at how we're enhancing security at the point of authentication. Okta has long led the way by supporting phishing-resistant authentication with Okta FastPass across Mac, Windows, iOS and Android devices. And in early 2025, we'll start supporting Linux machines as well. But think about how you unlock your actual Windows or Mac computer. In most enterprises, this remains the final frontier where using a password is sufficient. Last year, we announced Okta Device Access to help customers secure their machines and ensure that security starts at power up. And over the summer, we took things even further by adding passwordless phishing-resistant authentication to Windows and Mac devices using FIDO2. And today, I'm excited to announce that we're taking this journey even further with a new capability called Extended Device single sign-on. Extended device -- so much excitement, haven't even told you guys what it does, but let's get into it. So what extended device single sign-on does is it improves outcomes in 2 major ways. First, from a security perspective, it ties the Okta session directly to the device using a hardware-protected key that's secured on a hardware chip on the device itself. This means that the Okta session is bound to that specific authorized device and cannot be replayed anywhere else. And from an end user's perspective, you'll simply sign into your machine. And from that point in time onwards, you're already signed into Okta. All your downstream applications will be automatically logged in. And at every login, we are constantly reassessing all your security risk signals. So in case something does change, we can step you up at that particular point in time. So not only is it faster and better for your end users, it is more secure end to end. Now speaking about active sessions, let's take a look at security post authentication. This is where Identity Threat Protection with Okta AI comes in. We announced it at Oktane last year. We made it generally available over the summer. And throughout the course of this year, we've been adding even more integrations. Leveraging real-time signals from Okta and the rest of your security stack, ITP continuously evaluates the risk of an end-user session and takes actions to contain threats. Leading security providers like CrowdStrike, Jamf, Palo Alto Networks and Zscaler already integrate with Okta using an open standard called Shared Signals Framework and trigger powerful in-line responses such as Universal Logout if a high-risk situation is detected. And now we've continued to expand our network of partners that shared risk signals. We've added Rubrik, we've added Workspace ONE and SURF Security, among others. We are also working with a number of applications that are highly adopted in the enterprise and have extended Universal Logout to PagerDuty, Zendesk and Dropbox. And any application built with Okta's Customer Identity Cloud will automatically support Universal Logout as well going forward. These are some examples of the deep integrations we've already built with the most prominent enterprise technologies. Todd talked about secure identity integrations. What we've done is it's not just for Universal Logout or shared signals across the entire identity security process before, during and after, we've been going ahead and hand cranking these integrations, working with tech partners to help make your businesses safe. In fact, over 125 deep integrations are available for our Workforce customers today. Applications like Google Workspace, Salesforce, Slack, Box, Microsoft 365, I could go on and on. But we've been like laser-focused trying to ensure that we can raise your security bar and support your entire stack. So let's bring this back to 3 key security outcomes from a Workforce customer perspective. First, we want you to take back control of your identity security posture. Second, implement the principle of Least Privilege with products like Governance and Privileged Access Management. And finally, continuously monitor and remediate identity threats in real time. All of this is made possible not just with the products, but with the deep integrations we've built throughout the tech ecosystem. And these integrations are only going to become easier to use and more widely adopted as the IPSIE standard takes off. This is just a preview of all the exciting innovation that we are introducing to make our customers even more secure. You are not going to want to miss the Workforce Identity Cloud Keynote at 2:00 p.m. this afternoon, where we'll go deeper into our Unified Identity Solution, share even more innovation, and you'll get to see it all in action. And now please welcome the President of Customer Identity Cloud, Shiv Ramji.

Shiven Ramji

executive
#44

Hello, Oktane. Good morning. How is everybody doing? Good. Thank you, Arnab. Here at Okta, we are building for every identity use case and for every part of the business, from IT and security teams, to marketing and digital teams and of course, the product and engineering teams. That's because customer identity isn't just about user names and passwords. It's where security meets revenue, where your brand meets your bottom line and where trust fuels growth. Now think about that. Developers are not just building applications. With each line of code, they are shaping security, revenue and business growth. It's a tall order. It's a tall order considering customer identity impacts everyone in this room and most people on this planet. When done right, it powers convenient, secure experiences for billions. That's why embedding IPSIE into every application is so critical to help every single application builder, build faster, without compromises, with continuous authentication, automated provisioning and integrations all right out of the box. Now we know developers are under more pressure than ever to deliver more and deliver faster. And many of you in this room are building applications that power our businesses and our personal lives. And you face real challenges as application builders, integration complexities, scalability issues, and adoption hurdles. When you build an application with Customer Identity Cloud, you will get IPSIE out of the box. It starts with giving SaaS application builders, the tools to streamline onboarding and provisioning a key part of IPSIE. Today, each application uses different APIs for user management. And developers are forced to spend hours building custom solutions, increasing the risk of human error, orphaned accounts and unauthorized access. With IPSIE, every application will be built with the ability to automate the provisioning and deprovisioning of users. This will be powered by SCIM, also a key part of IPSIE. Now not only does SCIM boost application security, but it also frees up developers so they can get right back to building, and we aren't stopping there. Next year, we will launch self-service SCIM. [Audio Gap] Now over the next decade, we believe we will see the rise of a huge AI agent ecosystem. Large networks of interconnected AI programs that integrate into different applications, and act autonomously on our behalf. To realize a world where AI helps us daily, managing tasks and making decisions on our behalf we must empower builders to securely integrate Generative AI into their applications. This is where Okta can help. Auth for GenAI makes it easier for you to build generative AI applications securely. Thank you. It is a series of features to help ensure that AI agents have least privileged access to sensitive data, secure API access for AI agents and implement human in the loop processes for AI agents to take action on behalf of users. In the customer identity cloud and keynote later today, I'll be walking through a demo of Auth for GenAI to show you how all of these features work together. I hope to see you all there. You will also see more exciting product announcements and demos and hear from our customers Siemens and Major League Soccer. Make sure you are there. Thank you so much. Back to you, Todd.

Todd McKinnon

executive
#45

All right. Thanks, Shiv and Arnab. To free everyone to safely use any technology, we have to solve the problem of identity-based attacks. It's the only way we can help the entire industry by working together. Tech companies, identity providers, all of us focus on this common goal that's going to have a huge impact on the world. As we wrap up, here are all the innovations we announced today, you can see it all in one place. Thank you so much to the R&D teams that have been working on all the stuff. I'm fired up about where we're going. It's going to be a lot of hard work. But at Okta, we love a challenge. We don't shy away, we lean in and we're going to get back to work. We have a great foundation to build on. It's a foundation we've built together, so give yourselves a round of applause. Thank you very, very much for being here today and being on this journey with us. Please enjoy Oktane.

Dave Gennarelli

executive
#46

Good morning. Welcome to Oktane in the Investor Summit at Oktane. I'm Dave Gennarelli. I think you guys know me from Investor Relations. You guys know, allow me some safe harbor. So we will probably be making some forward-looking statements today. Please refer to our SEC filings for further information. . So with us today we've got Todd McKinnon, our Co-Founder and CEO; Jon Addison, our CRO; Brett Tighe, our CFO; and Eugenio Pace, our President of Business Operations. This format would -- this is going to be an open Q&A format. So this next hour is for you. Reminder, there is an online audience, but the questions will be coming just from this room. So with that, I want to turn it over to Todd, who's going to make a couple of opening statements, and we'll go from there.

Todd McKinnon

executive
#47

Yes. Thanks for joining us. It's an important session, and I look forward to the conversation. When I was reflecting on the keynote we just delivered really during rehearsals and thinking about the themes and the focus and the genesis of a lot of the products. It really is, I think, I'm really happy with how it went, first of all. And I think it's a good balance of a new twist and new emphasis in certain areas along a consistent theme we've had for many years. And that consistent theme we've had for many years is more integrations, deeper integrations, more capabilities across the entire technological ecosystem that identity connects to delivering more value out of the gate for customers, whether it was 10 years ago when we first had the Okta Integration Network and then we added different types of integrations, and we're working really hard to integrate Okta actually into the devices with things like FastPass over the years and on and on and on. And really, the big change here this year is, we've evolved from, I would say, the first 10 years of Okta was working with standards and around standards. And now we're really trying to lead the industry and define the next standard, and that's why this IPSIE standard is so important. But we're not going to turn into a company that waits around for standards. We're building the next generation of integrations and while at the same time, trying to put all the pieces in place to have the standards to be adopted with -- by supporting them in customer identity cloud and by doing the secure identity integrations we announced. And then around those integrations, obviously, is this what's become a very powerful set of capabilities with all the different products around governance, privileged access, Okta Privileged Access and the whole workforce suite. So it's -- I think it's -- you want a combination of new frontiers and new twists, but you want a consistent long-term strategy and that it's been very consistent and long term for us. And that is we're going to free everyone to safely use any technology, we have to do it by integrating better than everyone, particularly better than any one vendor that's trying to build the one-stop shop for everything security, the one-stop shop for everything. We're trying to focus on identity and have the best leading product in every category of identity and then really lead everyone to connect to the ecosystem, and that's going to solve this problem of identity-based attacks because when we go out to talk to customers and prospects, the security is the burning platform. And when we can be involved in that conversation, everyone has more value faster and more success factor. So that's faster. So that's an important part of the messaging as well. So yes, I think with that, we'll just open it up for questions and get the conversation started.

Joseph Gallo

analyst
#48

Joe Gallo, Jefferies. We've been hearing about tens of thousands of IGA customers come up for grabs as legacy vendors show end of life. Are you seeing the same opportunity in the next couple of years? Maybe talk about IGA product positioning and then how we should think about the capabilities of potential in fiscal '26?

Jon Addison

executive
#49

So we're pleased with the progress on...

Todd McKinnon

executive
#50

You have 10,000 customers in your commit. That's what I heard. It's out there. It's possible.

Jon Addison

executive
#51

We're at 1,000 customers already on OIG. And I think that if you look at our 19,000 installed base, it feels as we're out there in the field talking to customers about their use of Okta. For many of them, it's a very natural progression to go from what's often the starting point with our customers around access management and then they'll start to look at some of the extended features around things like life cycle management and workflows. And for a lot of those customers is a very natural evolutionary step to talk to us about OIG. And so that's, I think, taken us quite quickly to 1,000 customers. I think that when you look at our installed base, customers right now are thinking about budget constraint, OpEx is the challenge, but they're very much leaning in with us and trying to understand about the full breadth of our portfolio. And so there's kind of a maturity that's playing out in terms of their leverage of our portfolio, that means governance and PAM are very natural progressions for them. And even when we're landing new logos now, we've got great examples of new logo wins who are coming to us, and they're actually going all in. We signed a very significant deal with the transportation company recently. And they came in and they bought the access management solutions, governance and PAM all first up. So I think I'm really pleased with how this looks in our installed base, but it's also very encouraging that when customers are coming to us to modernize their identity platforms, they are seeing the full portfolio as something they're willing to commit to straight off the bat. So I think it's encouraging in both those aspects.

Todd McKinnon

executive
#52

I think the other part would be encouraging. Just yesterday, I was talking at the Expo with one of the GSIs and one of the first topics we talked about was how they can get more involved in governance because I think from a GSI perspective, they can add a lot of value, we can try to help them. And we -- obviously, we need to sell a lot more customers than what we've done. We've done 1,000, like Jon was saying, and we got a lot of left out there, but it's exciting to see the potential inside the customer base and also outside the customer base.

Unknown Analyst

analyst
#53

[indiscernible] from Truist Securities. Todd, you mentioned your $1 million-plus customers are your fastest-growing cohort. You've got around 40% penetration in G2K? What do you think investors are not appreciating about the significant expansion opportunity in the set? And do you still think there's a lot of runway for growth left in these larger enterprises as you go forward?

Todd McKinnon

executive
#54

Yes, the 40% in the G2K is a little bit of a -- as currently used in those accounts, it's a little bit of a vanity metric, meaning that it's not like we have 40% of the Global 2000 that are wall-to-wall in Okta. So there's a tremendous amount of upside there. Many of those deals are -- there's a presence, but it's part of -- it's a subsidiary or it's a smaller deployment because once you get into a Global 2000 Customer, a mid-market customer or even a mid-enterprise customer, they're not going to do part of their employees on one thing and the rest on something else. But Global 2000 is much different. The projects to get fully implemented take a long time, multiple years, if not longer. And in our presence in the Global 2000 has a tremendous amount of upside. In my conversations with investors, I think we need to have a better way to quantify it, quantify the potential there. We use the $1 million deal cohort and we use the over $100,000, which doesn't really tell you much about the Global 2000 because it doesn't -- you don't have to be a very big company now to spend $100,000 on Okta a year. So we got to, I think, maybe do a better job quantifying that with external metrics.

Patrick Edwin Colville

analyst
#55

Patrick Colville from Scotiabank. I want to ask about the 2 recent products in GA, posture management and threat detection. If I'm not mistaken, they're both 2Q GA. I mean, of those 2, how should we think about the directory for adoption? And then also, I guess, Brett, what's like the spend uplift as you go from an SSO MFA directory customer to add threat detection or posture management. Is it like a small uplift or pretty sizable for those 2 products?

Todd McKinnon

executive
#56

Maybe we can maybe start with Jon and then I can chime in from the product.

Jon Addison

executive
#57

I think with both of these products, it's very early days. I think with threat detection, there's clearly like some great synergy with existing Okta customers. And we've already had some immediate wins where we're looking at cross-sell and upsell, and customers are coming to us and looking at device access, threat protection and OIG. So again, it's just like rounding out the full breadth of the portfolio for our existing customer base. So I think that's a very clear upsell opportunity. With secure posture management, I think that also has relevance in our customer base. We had a great financial services win, quite a security aware financial services company moving fast into the cloud, their existing solutions to a lot of hand cranking and secure posture management. Like they got to value in days and not months, but we also see secure posture management as a bit of a beachhead opportunity for us to get into accounts, and it doesn't necessarily have to be an Okta installed-base customer for workforce for us to go in and show great time to value, specifically in that secure posture management environment. So very pleased about how the teams are getting enabled. There's a lot of excitement around both of these products. And looking forward to the future with them.

Todd McKinnon

executive
#58

Yes. Identity Security Posture Management, it's a qualitatively different product for us because we've never had a product that just scans the environment and assesses risk and tells you what you need to remediate. Our products have always been proactive in the sense of, or maybe the right word, but they've actually been authenticating people and creating accounts and actually operationally executing things in the workflow and in the access management process. Posture management is different because it's more like a traditional security product and that it scans the environment, detecting potential threats, detecting potential issues, and then initiating workflows for those issues that can be remediated by Okta Privileged Access or Okta Identity Governance. So as Jon was mentioning, it really gives us a very compelling entry point for the security person in the account, the CISO or someone in the security group, which traditionally has been an influencer in the identity decision, but not necessarily the primary buyer of it or the driver of it. So it's a very important part of our strategy, and the early success there is really, really encouraging.

Brett Tighe

executive
#59

Yes, in terms of the uplift, we don't have enough data for you yet. Once we do, we'll give you some more information on that.

John DiFucci

analyst
#60

It's John Difucci from Guggenheim. Brett, I want to talk for 20 minutes on CRPO, I'm only kidding.

Todd McKinnon

executive
#61

The CRPO keynote is later this afternoon.

John DiFucci

analyst
#62

Actually, I wanted to come back to what you started with Todd and bring in actually Joe's first question. So everything you were talking about, to me, sounds like a word that's often overused and I'm glad you didn't say it, but a platform. And it really seems like today, there is room for something, an identity platform where you bring together all the functionality of identity which you couldn't do 20 years ago or actually, was it 20 years ago, yes, it was actually that long ago. And I worked with one of your shareholders back here. He was my senior analyst, but when we were looking at things like this. So -- but when I think about what Joe asked, there is this opportunity for IGA to rip and replace, but that's because lot of the legacy solutions just failed. And they didn't fully meet their potential, but it's only been a large enterprise solution. And PAM has to, for the most part. So Jon, when you say you have 1,000 users on your governance product, is that -- are those like rip and replace because it just seems like your sweet spot, yes, you sell into a large enterprise and you want to sell more into it. But you also sell to the mid-market and you sell to the small enterprise and even the small business. And the IGA and PAM seems to me to be solutions that could be used in those areas, but the products just couldn't be up until now. And what your strength is, you brought identity to the masses from the start, the core IAM. And could you be doing that today? And the answer to the long-winded question is, out of those 1,000, are they rip and replace? Or are those greenfield opportunities?

Jon Addison

executive
#63

Well, I think we're seeing opportunity in all segments. I think we are seeing with our approach to governance a lot of customers are just coming into governance for the first time in our product. And so obviously, companies that have grown up with us as their identity standard and their platform of choice. For them, it's a very natural progression to get into governance for the first time with us. In bigger customers, obviously, most of them have a legacy with on-premise solutions. And so for them, it's a question of, okay, how do we start? Is this just the cloud applications? Do we have a coexistence strategy for sometime and how do we kind of start to think about a longer-term strategy as we move more broadly to the cloud where we start to think about deprecating some of the legacy solutions that they've invested in and that they spend a lot of money on. And so I think the challenges around some of the budgets that we were talking about and was mentioning earlier, that's kind of driving some of that, which is in and around how do we reduce the cost of ownership for governance in our company, how do we use that to drive further cloud adoption. And I think for us, that's a really good opportunity going export with them.

Todd McKinnon

executive
#64

Almost 0 of them are replacing Oracle or CA governance, almost 0. The next, I would say, maybe 20% are replacing something more modern like a SailPoint. But that's a relatively small number. And I would say, the majority of the remaining, they're putting it around something else. So they're keeping SailPoint and adding Okta to the apps that are easier to cover with Okta and then the rest is greenfield. . So the surprises there, if you would have asked me 2 or 3 years ago, I would have not thought that as many people would put Okta around SailPoint. Rather they would like to pick one and either Okta or SailPoint, but the coexistence seems to be more prevalent than I thought, which is kind of not surprising given that once these things get in, they're hard to change. So that's how we're seeing it.

Gray Powell

analyst
#65

Gray Powell with BTIG. So I'll have to admit, I'm a little intimidated. John's question is really hard to follow. But I'm going to do my best here, if that's okay. Okay. So Okta has had a lot of success in the past, helping customers connect to workers and applications and just winning on ease of use for lack of a better phrase. But today, some of the areas you're getting into like privileged account management, posture management, those are more security-centric buyers. So I guess like how does that change the conversation? How do you get customers over that hurdle? And just how is the conversation on security different today than it was like a year ago?

Todd McKinnon

executive
#66

Yes, might be a good one for you to start with.

Jon Addison

executive
#67

Well, I think what we're seeing with the breadth of the capability and the offerings that we've got is that we have to service quite a broad range of buying personas. And that's the reality of how we have to go to market right now. So whether that's the CISO org security operations, the CIO and obviously, with our SAM offerings, it's much more around VPs of engineering and digital. And so we've got to scale to the needs of a very broad number of constituents. And so as we've started to like really enable and educate the field organization with this broad range of capability, like it's going to take a bit of time for a lot of that to land. And so we're thinking as we go to market about what that means. We're considering aspects of focus in the future and specialization that might help address some of those challenges. And so I think that we have a very, very broad opportunity. But each of the buying personas and the business drivers around that capability set is quite diverse. And so we have to think about how we evolve to meet the needs all the time.

Madeline Brooks

analyst
#68

Madeline Brooks from Bank of America. Brett and Eugenio, this is going to be more for you guys and not to bring CRPO up again. But I think a lot of us are starting to think about more single-digit growth for next year, and I'm not going to ask for any type of guide. But if we think about that, how should we think about margin structure? And where could you get a little bit more expansion on the margin?

Brett Tighe

executive
#69

Yes. I mean, from a margin perspective, we've been working on it for a few years now. It's a lot of what we've done. It will be just that continued, right? So if you remember, a couple of years ago, I talked about real estate rationalization, talked about software rationalization, just being more cost conscious. And then the big one was around low-cost regions, right? We had very few people in low-cost regions. We've done a heck of a job across the entire company over the last 12 to 18 months on expanding that percentage, and we believe there's more opportunity as we go forward. And so that's really where we think margin can come into play is really from the low-cost region folks. And you can see that even in this year's margin guidance, that we're reinvesting that back into the business. So we talked a lot about security today at the keynote. You've heard a lot about the Okta Secure Identity commitment. You've heard about us really doubling down and becoming one of the most secured companies in the world. And so we've been taking some of that savings and investing it back into these key priorities even in FY '25, we're going to continue to do that in FY '26 because we believe this is a massive opportunity in front of us. And so we're going to continue to balance the growth and the margin profile just like we have done in the past.

Eugenio Pace

executive
#70

Yes. Just -- I'm sorry to add on that. The existence of a centralized operations team has brought inefficiencies by itself because we don't have to traverse a complicated org charge anymore. It's all in one place. We have faster decision-making, we can ship things faster, et cetera. To the low-cost expansion, BT, which is part of my team, the technology team in our company has a big investment, so growth investments in India, as an example. And we're going to be doubling -- almost doubling the team there. It gives us access to amazing talent, which is primarily the first driver, it's like assembling teams that can execute more quickly and obviously with a different cost profile as well.

Madeline Brooks

analyst
#71

Maybe just to clarify what you said, Brett, I think this is one. How far into the security hardening do you think you are from an Okta perspective?

Brett Tighe

executive
#72

I'm going to let Todd answer that question. He is the expert. I mean, I could give it a shot, but go ahead, Todd.

Todd McKinnon

executive
#73

I think the last -- it's been really a process of the last 3 or 4 years with a very concerted doubling down in the last year. And I think next year and beyond, you'll see more of a normalized long-term level of investment and focus there that will keep us at the level we are now.

Eugenio Pace

executive
#74

Yes, on the infrastructure. Infrastructure is one of the pillars of OSIC. OSIC, I think has been really, really well received by our customers and the broader community. Internal infrastructure, which I'm responsible for, as I said before, has been a big focus. And I'm a big fan of ISPM as a user. We drink our own champagne at Okta and even though we run a pretty tight ship, it's amazing how good that product is. We made a lot of progress.

Brad Zelnick

analyst
#75

Brad Zelnick, Deutsche Bank. Thanks so much for hosting us today, and congrats on another great Oktane, which I know Difucci probably wanted to say too, he just forgot. But I wanted to talk about the international opportunity, it remains significant, roughly 20% of your mix today and obviously headroom to be much, much greater. And Jon, I believe, if I'm not mistaken, you just replaced your prior role with a really strong leader in EMEA that comes out of the GSI world, which makes me wonder, a, the strategy, how much does it depend on partners to really be effective for us to see international get to 30%? And I don't mean to leave out APAC, but EMEA is obviously the bulk of what international is today for Okta. And then even as we think about the strategy and how it's different and how you leverage partners, how should we also think about the economics of going into international markets and the cost of acquisition for these customers?

Jon Addison

executive
#76

Well, I'll start maybe with a little bit about the expansion and maybe you can pick up on the economic piece. But so we've been investing in international through our own direct investments and obviously through establishing a partner strategy in the regions that we're focused in. And very pleased with the progress in both of those areas. I think we've got very strong and stable leadership now in our markets outside of the U.S. I think that where you see the progress, then it's clear that the progress is in the markets that are cloud forward and they're -- like no prizes for guessing which ones those are. And I think even now when we're starting to see kind of some of the real marquee customers that you expect to come through in those markets and the impact that just has on like local references and really starting to build strong penetration in multiple segments and in some of those marketplaces, we're leveraging hubs to allow us to do that, so we're building in Dublin, we have been building for some time now a hub that's really focused on the SMB bid market and the emerging markets outside of the core markets in Europe. You can start to see a kind of multilayered strategy of investments in markets for field, investments in markets for hubs and a partner strategy that leverages the work that we're doing in HQ in North America with some of the big international systems integrators. And that's really playing out well, not only in the core international markets but also in emerging markets, and we're starting to win like really great Tier 1 logos in places like the Middle East and Africa, as an example. And a lot of that is influenced by the impact of some of these GSI relationships out there in the peripheral international markets where we don't have a presence. So I think partners are going to be a very, very fundamental part of international expansion. In some markets, we're highly committed to our partner-first strategy. So fully loaded transactions through partners in Tier 2 markets, activating those markets indirect only, very clear priority for us as we look to grow our international ecosystem. So I think that the economics of that is a combination of those things, where we're investing directly. There are some markets where we haven't got current legal entities and direct investments, and we're looking to expand those through partner penetration.

Brett Tighe

executive
#77

Yes, I would just add to the unit economics of the countries, it definitely differs based upon which way we're going. Obviously, if you go direct, it takes time to get the 747 off the ground, if you will, right? You got to use some fuel to get it off the ground and the unit economics aren't as good. But in the long run, as each one of these countries mature, we find better unit economics over time. It's just a matter -- not everybody knows Okta in every country like they do in the U.S. We have to recognize that. And some of the things that Madeline was asking around margin doing low-cost regions helps us fund things like this to be able to make sure that we're investing in the right places at the right time.

Todd McKinnon

executive
#78

I'll add just over the top of that more focus on partners and partner enablement and partnering in broader parts of our business from demand generation to closing the sale to servicing the customer to supporting the customer is a big focus for us. If we're going to get to our long-term goals, we're going to need across the whole company to improve and deepen and mature our partnering approach. We've made good progress, but we can do a lot more, and it's really a big important focus for us going forward.

Darren Baker

analyst
#79

Back here in the middle. This is Darren Baker from PRIMECAP. I wanted to follow up on Madeline's a little bit, and I'm going to be a little blunt here. So I hope you'll forgive me for that in advance. Look, I think for most of the investors in the room, the biggest concern that we have is really about the growth trajectory, right? And when we think about the possibility that Okta could be growing single digits, I mean, that's usually kind of a domain that we think of as afflicting much larger companies with legacy technology or just in much more mature markets. And as we listen to your presentation here, you see the energy and the number of attendance, people in the hallways and things like that, that doesn't feel like the environment that we're in here, right? At least, I'll speak for myself. It feels like there's a tremendous amount of initiative taking place at Okta. There's just a rapid pace of innovation, really trying to address what customers are looking for, pushing forward new standards, all kinds of things like that. So I will -- again, speaking for myself, like I'm just trying to square like where -- how do we line up kind of that growth trajectory with what feels like a much greater level of kind of confidence and momentum qualitatively that's coming out of an environment like this. So I'd love to just hear your kind of latest thinking on how those conversations with customers are going, what's holding them back if they are kind of slow walking the process of expanding the relationship with you? I know that new customer adds have been a little bit weaker in the recent past and so what might be slowing down customers who clearly have identity infrastructure from potentially making a move over to the Okta platform, anything like that, just to help us think about kind of the medium-term trajectory of growth here and what catalysts there could be that could kind of get things going again?

Todd McKinnon

executive
#80

Yes, we appreciate the question. Don't be afraid to be blunt anyone. We love that. We are -- growth is very important to us, and we don't like the deceleration either. We are very focused on reversing that trend and trying to grow faster, while at the same time, making sure we continue to focus on profitability. We're at a scale now where we should be able to grow and be profitable. When I look at the -- I think right now, it's a timing thing, in a sense of when the growth initiatives are going to kick in. And I think, obviously, in the numbers, we're not seeing them kick in yet. But as you mentioned, we're very optimistic. And I would go in order of kind of things I'm most optimistic about for driving growth. Our -- number one is large enterprise. We talked a little bit about it with a Global 2000. Okta is really -- our success was built on, call it, mid enterprise. And the reason that the $1 million-plus cohort is the fastest growing is because there's still a ton of potential in the large enterprise. A lot of these companies have been reticent to adopt a cloud-based identity approach for a couple of reasons. One is just their own internal infrastructure has been -- they've done cloud, but in terms of the center of gravity, big enterprise has to have a lot of cloud for it to be like the default where they choose to put their security tools and something as sensitive as identity. So that's really starting to happen more and more now, and we're very optimistic about that in the future. It helps that we have this broader platform. So my -- the second thing I'm most excited about after large enterprise is the ability to sell these new products. Governance, we've talked about that, privileged access, the idea of the whole suite being something that we can sell. Identity security posture management, of course, don't forget about customer identity. That's a big growth driver. So we're really excited about that one as well. And then I think the third one also we just talked about. Internationally, I think we've made a ton of investments in these Tier 1 countries, we're partnering in others those investments. We're optimistic about those showing up. But talk is cheap, right? We have to continue to work hard and actually show the results. We're not satisfied until we can do both, grow and be profitable.

Adam Tindle

analyst
#81

Adam Tindle with Raymond James. Todd, I'll ask a blunt strategic question. In your keynote, you talk a lot about wanting to basically stop identity attacks completely through sort of prevention. Another thought might be to accept that there's -- identity is going to be an attack factor. It's not possible to stop 100% and shift all of that investment to detection and response. We asked that because CrowdStrike, for example, has built a couple of hundred-million-dollar business in ITDR from 0 just over the past couple of years. So strategically, why such a focus on the prevention piece versus detection and response? And if you can wrap in your view on how you see ITDR evolving over time, particularly relative to players like a CrowdStrike who's built such a big business and how that might change going forward?

Todd McKinnon

executive
#82

Yes, it's a really, really insightful question. I think the stop in the attacks is probably -- as you call out, it's maybe a little bit oversimplifying it. The deep dive is what you're saying. I mean -- and you know in Arnab section of the keynote, he talked about before authentication after -- during authentication and after authentication, then security posture management to assess the vulnerabilities that log in with things like phishing resistant, FastPass. And then after authentication actually continuously evaluating the threat landscape and having different layers of the security stack, the CrowdStrikes, the Palo Altos, the Zscalers, the Microsofts be able to share signals with us and the attack -- malware attack can happen, but you want to prevent it from moving around. So I think that is the right way to think about it. It's not -- I think it's really simplistic to think that you can literally stop all these attacks before they ever happen. It's a combination of all 3. Specifically, the CrowdStrike, I think that their business around identity security is interesting. And when we launched our identity threat detection product and later on the identity security posture management, we had really frank conversations with the team talking about should we really get into this, like CrowdStrike is a security company, they're awesome at that. They're going to take on identity. What do we -- how do we have differentiated value to add? And the answer is, what we're really good at is building integrations to thousands and thousands of different applications. And to have ITDR for the entire ecosystem, you have to have the integrations everything. You can't just say, it can't be super simplistic and happened just before log-in and has to be deeply embedded into the whole session of those accounts. And that has to be done through standardization like IPSIE. It also has to be done with our integration factory that we're really good at. So CrowdStrike's business is, they're evolving it now, of course, because they see some of the similar problems we see, but it's built on on-premise legacy active directory, which is, you can build that integration once, which the company that they bought built, this company called Preempt. And you kind of get it everywhere. But the world is changing. And there's a reason why Microsoft is not betting on on-premise architecture for the future because the future is SaaS and AI agents and cloud, and that's where we're going. And the one -- the key argument why strategically, we got into that business and how we can differentiate, it's coming back to this core differentiation of building these integrations at scale, which is a combination of hard work, a platform that can do it, standardization, culture in the company that's really good at this. How many companies have a culture that wakes up every day and says, "We're going to try to integrate to 7,000 things." Not many. So that's our differentiation there.

Eric Heath

analyst
#83

Eric Heath from KeyBanc Capital Markets. Maybe just to come back to the growth equation and focus on SIEM a little bit. Maybe if you could just help illuminate us a little bit more on just why it's been a little bit more of a pronounced slowdown and obviously getting back to the future here, but what you really feel like you can do to reinvigorate growth there? And feel free to tell me I'm wrong, but it feels like it's just been such a big point of friction to convince customers to say, hey, homegrown is not the right way. You need to switch off homegrown solutions to a commercial solution. So it seems like it's been a big point of friction to catalyze that change. So maybe you can just talk about if I'm perceiving that correctly and what you can do to catalyze that change?

Todd McKinnon

executive
#84

Maybe from the go-to-market perspective, you can start and then all.

Brett Tighe

executive
#85

Well, I think you rightly identified that the conversation that we're in is the build versus buy conversation. And so it takes -- I think this is still a very early maturing market, right? This is a very big market, but I think it's still very early days. And so we spend a lot of time technically evangelizing, right, with companies of all sizes about the benefit of buying a platform of this nature for consumer apps, digital platforms. And we've acquired all 0, and we've spent a long time activating and enabling like the level of awareness that's required to govern and have that technical evangelism story really nailed down with customers across our sales organization and our presales organization. And if you look at the work we've done this year, like we really -- like for most of half one, we basically spent all enablement cycles on CIC enablement. And I think that when you look at what are the measures of the progress that we're making in terms of taking CIC to market at scale internationally and in the U.S., one of the things we track is AE participation rates. So we've made progress every quarter with that. And so we've vetted the capability to go and have those conversations into the field now and I think that we've reached a point of maturity with that. But I just think in this environment, a lot of customers and prospects are taking time to really weigh out their options, and they've built development teams, and they've been powered those development teams to build software. And a lot of the time, what we're trying to do is to get the platform into the hands of those developers either through our freemium motion and we've made some changes there, but it's really designed to fill the top of our funnel with a lot of pipeline that over time is going to build. And once we get the product into the hand developers, then we know they get to that [indiscernible] and they upgrade to the paid offering. So I think we've done a hell of a lot of foundational work this year to get that right, and I'm very excited as this market really matures that we start to see the fruits of that over the coming quarters.

Todd McKinnon

executive
#86

The other thing that's -- just real quick, Brett, the other thing that's driving the numbers of that business is that a lot of customers overly optimistically bought seats or monthly active users. Just like on the workforce side, we've seen with companies downsizing their workforces that puts a little bit of pressure on the natural motion that used to happen when contracts came up for renewal, they just expanded seats and added employees. Customer identity side has the same phenomenon, meaning that 2 or 3 years ago, if you needed 1,000 monthly active users, you probably were going to buy 1,500 just because everything is great, everything is optimistic. Now if they need 1,000, they're probably going to look about how they could get away with 750. So that dynamic in that "rightsizing" for a more -- the new normal, not the 0 interest rate environment that we were in a couple of years ago, that's driving the growth rate that you see a little bit, but it doesn't change the fact that this is a big opportunity and that we have the leading products in this market by far.

Brett Tighe

executive
#87

Yes. I was actually going to say that, but I also add something as well, which is, in Q2, we saw the number of customer identity deals grow quite swiftly. But the problem what Todd was just talking about, is the number of monthly active users on average has gone down by a fairly significant amount as people are being more thoughtful with their contractual agreements. So you see that directly in the ACV results that we provide on a every other quarter basis. So we're adding them and just the unfortunate part is you're seeing that MAU headwind related to the macro because number of products is about the same. price is about the same. So your ASP is going down because you've got less units basically being purchased because people are just being more thoughtful at this point with their agreements.

Gabriela Borges

analyst
#88

Gabriela Borges, Goldman Sachs. Todd, I've heard you a handful of times now consistently respond to the question on how do you reaccelerate growth by saying large enterprise. It's the first thing you normally talk about. So maybe just to expand on your earlier comments, within the large enterprise, what's incrementally changing around the willingness to invest in cloud infrastructure? And why is Okta better qualified for that opportunity today versus maybe 2, 3 years ago? And perhaps Jon, you could comment as well.

Todd McKinnon

executive
#89

Sure. I think one of the things that we're really striving to do is to surround our customers and prospects in enterprise and strategic in the G2K with partners who can consult with them about transformation to deliver incredible value through identity management in the cloud. And that's a long-term play because working with GSIs -- companies to build their levels of awareness and to really deeply understand how they can grow meaningful services practices around Okta, that's going to take time. But we really feel strongly that we're making great progress there. And so if you look at some of the feedback that we had from the GSIs, who came to Partner Summit this week, I mean, some of them have materially grown over the last year or 18 months, their business practices around Okta, whether that's in dollars or in terms of the number of partitioners that are now activated and able to do work. And so when we think about winning in the enterprise, a really big part of that is making sure that we are influencing the enterprise. And we've only got a certain amount of capability to do that at scale and that's a very big part of our strategy. So we're focused with our own resources, very strategic partners and that we have a long-term vision with those partners to understand how to consult with customers over these very generational decisions so that it's a win-win-win for all 3 of us.

Jon Addison

executive
#90

I'm working with an early-stage prospect with -- it's a massive financial services company, and they have 500 SaaS applications, 1,500 applications they run on public cloud. So it's applications they built or they bought that they run them themselves on the public cloud and then 5,000 that they run in their own data centers. And they are talking to us about being the identity standard across all of them. Now when they look at that equation, that's 7,000 apps. And a cloud service that's most integrated to everything in the world is only going to be compelling when the 1,500 plus 500 gets big enough to where it's kind of some reasonable share of the whole total. And so sometimes it's as simple as that. It's like the center of gravity of their IT has shifted enough where they really say, hey, we can have one identity layer across all this, and it makes sense to do that in the cloud because now 2 out of 5 of their applications are in the cloud now. And it's a combination of just trust and maturity and scale that Okta has been able to deliver. They look at 300,000 users at FedEx. They look at all of our large enterprise customers across the board, and they just get more comfortable with it, and they see that it's flexible and can be deployed quickly and have a -- they aren't going to have to have multiple vendors for all the different areas we cover, and it's not -- I wish that would have happened 5 years ago or 10 years ago, but the second best time for it to be happening would be now.

Roger Boyd

analyst
#91

Roger Boyd with UBS. Todd, in your keynote, you talked about reinvesting in customer identity solution, I think, separately from customer identity cloud. With that product having effectively lived within Workforce Cloud over the past few years, should we view this as a desire, maybe better define the CIS road map separately from workforce or customer? And if so, why now?

Todd McKinnon

executive
#92

We have a lot of customers that need it and rely on it and they don't want to migrate. And we -- I think a couple of years ago, we thought that the enhancements they get because it's on the same platform, these are significant things. Like for example, one of the things we added to the Workforce Identity Cloud in the last couple of years is an overhaul of the framework that you grant administrator role access to the whole platform. And that's going to be super beneficial. You're going to like define the admin roles and do that scalably and manage the life cycle, whether it's a customer identity use case or workforce. These are significant enhancements. And I think we thought that, that would be enough for these customers. And I think what we're learning is that they want more specific customer identity integration. And I think the incremental investment there for us is well worth the path, if you see the size of the business and the importance -- the strategic importance of those customers.

Michael Cikos

analyst
#93

Mike Cikos with Needham. I know we've gotten a couple of questions on the growth dynamic. And one of the things that I think all of us are trying to figure out, we're calling out see headwinds, could you help us think about where we are in the renewal base and how those seed headwinds are playing out? We're talking about them in Q2, but like are they still getting worse? And then any commentary on those seed headwinds as well if we try thinking about workforce identity versus customer identity?

Brett Tighe

executive
#94

Yes. Seed headwinds, we believe, last through the first half of next year. We're doing that based on when the contract started. So we -- our data suggests that the longer you're back into the COVID area, the more challenging it could be. So for example, if we had a deal that was signed in FY '24, we don't think that's part of that cohort. If it was signed in FY '21, there's more likelihood that there's been some overpurchasing like Todd was describing on the unit basis. That's based on the current macro economy. Obviously, if it gets worse, maybe that time frame extends out. If it gets better, maybe it gets a little bit shorter. But that's our assumption based on the cohorts as we see them today and how they've been performing based on the renewals we see. In terms of workforce versus customer identity, I would say, it's probably a little bit more on the customer identity side, but it exists on both sides. It's something we're seeing in both sides of the business.

Michael Cikos

analyst
#95

Just to be clear on that, the first half comment for next year, like is that when you think it will be largely behind us? Like is most of that pain already behind us? Or is there like...

Brett Tighe

executive
#96

We think the majority of it will be behind us by the end of the first half of next year. But this is something that happens in every economic cycle, even in a good one, people go bankrupt or people overpurchase. It's just -- we think that the magnitude of it will be lessened and will be more normalized once we get into the back half of next fiscal year.

Todd McKinnon

executive
#97

I think we don't see it getting worse. We just don't know when it's going to get better, that's how I would put it.

Peter Levine

analyst
#98

Peter Levine with Evercore. Todd, to your comment earlier on the growth initiatives, not yet kicking in. So maybe like what's underlining that remark? It sounds like macro is a piece of it, but is it the majority? So maybe help us understand, is it educating the market? Is it competitive landscape given how fragmented it's become? Or perhaps was it the biggest pack from last year? Did that derail your plans? And as we now anniversary what happened last year, can you give us an update on how those renewal cycles have played out given what your expectations would have been?

Todd McKinnon

executive
#99

It's -- I think in terms of macro, we think this is the new normal. We're not -- we think this is the environment we're in and as Brett mentioned, it's always possible it could get worse, it's always possible it could get better, but we're not sitting around waiting for it to get better. We're hard at work trying to improve growth rates in this environment. I think the -- we've talked about the impact of the security issue from last year, and it's hard to quantify it when you look at the numbers. But it's likely it's had some impact. And so I think there is something to be said for lapping that. And more importantly, I think there's something to be said for the market and the prospects and the customers seeing everything we've done there. We talked about a lot of it today. I think that's potentially very powerful, and we're very optimistic about that. And I also think that these -- we've talked about the large enterprise and some of the dynamics there. Some of these products -- products have to be new at some point. So they don't just go from 0 to 100 overnight. And governance is the most, I think, mature of the new offerings, then privileged access is a contender for the next one. I think another interesting one is the combination of security posture management and identity threat protection. I think in a year from now, it might be a toss-up like which one we're talking about more bullishly. I think both of them have the potential. And then, like we talked about customer identity. So I think there's a lot of opportunity on the product side as well. So hopefully, that helps.

Andrew Nowinski

analyst
#100

Andy Nowinski with Wells Fargo. So you guys have built arguably one of the most comprehensive identity platforms in the industry. And there's no question, I think it's better than Microsoft. But what are customers telling you when you lose a deal to Microsoft? Is it just price? And what can you do about that?

Todd McKinnon

executive
#101

I think it's good enough. That's what they say. It's good enough. And we -- our argument is that, especially with the increased focus on security and the identity security products we have is good enough, good enough, probably not. And I think there's also a strong correlation between how sophisticated a customer thinks about identity and whether it's good enough or not. A very simple way to think about it is, simple, single sign-on to a few SaaS applications is not very sophisticated. Complete integration to identity governance workflows and HR onboarding, et cetera, et cetera, that's where our differentiation really shines. And we're, of course, working hard to really extend and enhance that differentiation. So everything we've talked about from IPSIE to really the 125 secure identity integrations are highlighting this point that good enough is not good enough and that some organizations that aren't that focused on technology, not be able to get away with having their e-mail system also provide their identity, but for the more sophisticated or ones that are more mature, it's an investment well worth making. It's going to pay back a lot of dividends over time.

Ittai Kidron

analyst
#102

Ittai Kidron from Oppenheimer. Thanks for hosting the event today. One small one for you, Brett. Can you remind us the attach rate of your customer identity solutions to your workforce solutions -- to your workforce customers? What's the penetration rate?

Brett Tighe

executive
#103

Yes. I mean it's still -- the majority of the customer base is still workforce. It is actually probably Jon, not probably -- it is Jon's biggest upsell opportunity right now. This customer identity, I know we talk about governance, we talk about PAM, we talk about threat protection, these are all amazing products.

Todd McKinnon

executive
#104

Right after the 10,000 people that are upgrading their...

Brett Tighe

executive
#105

Yes, we're after that. But it really is the biggest opportunity we have in terms of the upsell deal sizes. Our biggest deal last quarter was a customer identity deal. It's -- there's a lot of room to run there.

Ittai Kidron

analyst
#106

If I can have a follow-up nicely moving the pressure on to Jon here. But Todd, I'm trying to think about identity on a more broader way. It's quite interesting how you kind of work the security angle into your presentation today. But longer term, identity verification is going to have to be a part of this as well, which is a little bit of a nontraditional kind of a way -- in the way it's being performed right here in the U.S. right now. How do you view that market? In what way will you need to partner with it or potentially actually own an asset in that market to broaden your identity verification capabilities?

Todd McKinnon

executive
#107

The identity verification you saw in the demonstration today, if you were able to watch the keynote, you saw a clear providing identity verification in our -- that market it's very -- the solutions are pretty verticalized, in the sense that there's different ones for gig economy workers, and there's a different one for Clear ID kind of started from airport and travelers, and it's pretty fragmented. So that's why we've taken this partnership approach. I think it's an area that needs to be standardized. So I think the evolution of the IPSIE standard and maybe other standards like that could cover this, because I don't think it's going to be a one size fits all. I think the -- particularly in North America, I think the model -- maybe in some countries in Europe, they'll be able to get to more of a digital verified ID. But in North America, it's most likely to be an ecosystem of people doing it. And our approach there is going to be integrated first.

Shrenik Kothari

analyst
#108

This is Shrenik Kothari from Baird. You covered the international opportunity and enterprise and just now you kind of brought a verticalization. So just a question on the federal side of things, which has been one of your fastest-growing verticals have consistently performed very solidly in the current quarter, tracker seems to be growing nicely and there's a lot of high interest here. Of course, the FedRAMP High certification is something that leverage our advantage in winning new deals. Just curious, like in the context of like other identity vendors also achieving FedRAMP High and trying to go in with the security first messaging, just curious in terms of -- you talked about the importance of the Washington, D.C.-based teams. Can you provide some more insight and color on how you're structuring those teams, the strategies that you're using to really kind of continue the lead and momentum in the federal sector just in the face of other vendors pushing harder?

Todd McKinnon

executive
#109

Yes, the largest customer -- in terms of ARR, the largest customers I've met with this week are all federal customers. So it's an important vertical for us. One thing that's interesting is that being -- really our roots being in the cloud and evolving as a cloud service, meaning that of the pure-play identity vendors, we're much more mature on our certification journey because if you think about it, all the competing vendors that started as software companies, they always could just ship their software. They never had to get FedRAMP certified because that's only for services. So it's given us some pretty important competitive differentiation there in that certification and how early we invested in it. We're going to continue to keep investing there because the government overall has a very -- they're very mature and sophisticated about buying identity solutions. And even I think our success in the federal government in the U.S. has, I would say, definitely been stronger than our -- I think we have more potential in just commercial large enterprise. I think our success in the federal large enterprise has been more. We've done a better job there. So it's kind of a good pattern to emulate as we go for broader large enterprise adoption.

Joshua Tilton

analyst
#110

Josh Tilton, Wolfe Research. Actually, maybe I'll sneak into since it's the last one. Todd, first, I kind of just want to clarify something you said on IPSIE. Do you think that Microsoft is going to participate? Or do you view...

Todd McKinnon

executive
#111

They're in the working group, for sure. Yes, for sure. The reason why -- like if you would have -- as you -- I know you follow us closely, so you know that we've been talking about this concept of pushing the way integrations work forward by providing tools on both side of the equation. So tools for SaaS apps that are going to be delivered to enterprises and also tools for workforces that are going to secure those apps. And the reason why we've had such a focus on this open standard is because the simple realization for -- to get this to work, all of technology has to adopt it. And I think it's -- and why is all of technology going to adopt it? They're going to adopt it because they know if they did, it would be applicable to every customer, no matter who they're using. So that's really important, right? So we got to open the standard work with Microsoft, work with Ping, work with everyone so that technology vendors will know when they comply with the standard, it will work everywhere. Now you might react like, oh, that's not great because then it's not going to be proprietary to Okta. True, but we made a basic calculation here that the reason why -- the way we make the whole identity industry go faster and accelerate faster and get wider adoption is make it easier and make it simpler, make it more compelling and deliver more value faster for customers, specifically around this idea of eliminating that [indiscernible]. So the way we do that is get together as an industry and make the pie bigger. And we simply believe that by being the thought leader and having the first and best implementation and iterating quickly and providing value, we're going to have a bigger pie of maybe a smaller percent slice. That's going to be much more valuable for us than a bigger piece of a smaller pie.

Joshua Tilton

analyst
#112

Makes sense. And maybe just a quick follow-up. I tend to keynote, I thought it was great.

Todd McKinnon

executive
#113

Well, thanks. We work hard. I'm glad you enjoyed it.

Joshua Tilton

analyst
#114

Your dad was there.

Todd McKinnon

executive
#115

Yes, he was. He's very proud. .

Joshua Tilton

analyst
#116

I'm, sure he is. My question, though is, I definitely felt like you talked about a lot of initiatives that you guys have been focusing on that have nothing to do with selling, but clearly take a lot of focus from everyone in the company. And I guess you talked a lot about improving the growth, but is there a chance that maybe too much focus has been put on things that have nothing to do with selling and you need to maybe reinvest or refocus or kind of reinvigorate the sales force going forward to drive the improvement in growth that you'd like to see?

Todd McKinnon

executive
#117

I think we -- I mean, I talked a little bit about the impacts of the security issue last year and although it's not quantifiable, likely had some impact, I think you're seeing there was definitely a diversion internally going through that, not only just helping customers through it and helping them manage through it in confidence and trust. But also just as you mentioned, what we've been focused on internally. It's not like the sales team has been working on the hardening our corporate infrastructure. But around the company, there have been IT projects that are -- didn't get prioritized that would have been business-facing and business benefiting that we've taken those resources and had them do internal security projects. So yes, maybe there's some short-term hit. But if we're going to be where we need to be over the next 5 or 10 years, it has to happen and it's been absolutely the right investment. Now I think what I'll ask my colleague here on the left about is, how do we take this and turn it into benefits in terms of go-to-market? And I was just on the way in here, I said to him, I turned over to Jon, and I said, "Hey, Jon, is this going to help us sell anything?" And why don't you tell them what you said?

Jon Addison

executive
#118

Of course, it is, Todd. It's a very, very good use of the company's money.

Todd McKinnon

executive
#119

It better something. It absolutely better.

Jon Addison

executive
#120

Well, I think from the point of view of the sales organization, what we've been through with the secure identity commitment, it's a really important part of how we're building trust with customers. And so it's very necessary that we have a clear message around the work that's been put in. And obviously, after the incident, we had to spend a lot of time with customers explaining and building trust again and working through their awareness of what it is that we're doing. And I think we've got increasing number of examples now where customers are coming back to us and saying, that's been a really formative thing for the company. And I think there's a lot of belief that the steps that we've made are going to build Okta to be an incredibly strong company in the future. So we're getting great feedback about OSIC and people want to learn about it. There's a lot of relevance in it to the challenges that they're facing. And I think it's a very strong foundational step.

Dave Gennarelli

executive
#121

Great. I think we have to wrap it up there. That was a fantastic session. Great questions. We appreciate you coming out today. We also have a one-pager, which is actually a 10-pager summary of all the product announcements that are coming out today. So that will be pushed out to you via e-mail for those online, you can also access it on our Investor Relations website, you can also access the replay of Todd's keynote this morning as well as a replay of this session. So and with that, enjoy the rest of Oktane. Thank weyou. . [Presentation]

Unknown Executive

executive
#122

Please welcome to the stage, the real Chief Product Officer, Workforce Identity Cloud Arnab Bose.

Arnab Bose

executive
#123

Hello, everyone. As you can see, we gave our marketing team access to GenAI tools, and they have gone completely overboard. I love a good viral marketing campaign, but we have over 7.3 million unique users using FastPass today, and it's rapidly growing. And I don't think my corporate card can handle all those 3 pizzas. Also, you all should have known it was fake. I love anchovies. Clearly, some people who didn't watch as much, teenage [indiscernible] decided growing up in the audience, [the booze]. But my legal team has also advised me to say that this is not a genuine offer. So I can actually say that. There is no free pizzas if you enroll in FastPass. It's good for you though, please, please enroll. Please get to phishing resistance. That's the future of authentication. All right. With that, let's see a show of hands. Where are my Okta admins in the audience today? How many of you are Okta admins? Wow. Wow. Please give yourselves a round of applause. Yes. Thank you. You are the leaders shaping the future of identity and security today. You know how technology is changing the world we live in because you are building it from autonomous driving cars to AI-powered, everything. And the glue that connects all of the technology together, it's identity. Take the Norwegian Refugee Council, for example. The NRC provides life-saving aid to displace people in over 30 countries, often in conflict zones and in remote areas. With Okta, NRC secures access to its nearly 7,000 staff members, ensuring that their critical work can continue uninterrupted. Wyndham Hotels & Resorts is also transforming how it operates using Okta for both innovation and business agility. Wyndham is the world's largest hotel franchiser by a number of properties with approximately 9,200 hotels across 95 countries. Okta Secure is access for thousands of Wyndham employees. Their franchisees saw a 75% improvement in operational efficiency, all the while improving security outcomes. But as identity becomes fundamental to everything that we do, it becomes central to everything, it's also become the prime target for bad actors. You've probably heard the statistic that over 80% of all breaches are caused by some form of identity compromise. But did you know that in the last year alone, almost 1.9 billion session cookies were stolen from Fortune 1000 employees. These are post authentication attacks. Even if you've got authorized and you've secured access, bad actors are getting in and they're stealing the session cookies to bypass MFA and other security checks or the deepfake, kind of like the one you saw upfront, but be more specific and harmful, deepfake incidents have surged by over 700% in the financial sector alone. This makes it easier for attackers to impersonate users and bypass security checks. When I look at these numbers, one thing becomes crystal clear. Identity has to be the foundation of your security strategy because identity is security. This is what informs the mission of Workforce Identity Cloud. Our mission is to secure the future of work for every organization and every person worldwide. No matter how complex your tech stack is, no matter how fast your business moves, identity is a piece of technology that powers your business and keeps it safe. Today, my team is going to walk you through how we're delivering on this mission in 3 key ways. First, by taking a unified approach to identity security, protecting your business before, during and after authentication. Second, as you heard earlier in this morning, we are leading the industry with a new open identity standard called IPSIE. And finally, this unified identity security platform or the solution is built to deliver utility-grade reliability, scalability and trust. To kick things off, please welcome to the stage, Christian Swanson.

Kristen Swanson

executive
#124

Thank you, Arnab. It's great to be here with you all. And like Arnab said, today, I am going to take you all on a journey to see why identity is security for every organization in the world. If you haven't met me yet, I lead our Research & Design teams here at Okta. And I spend a lot of time learning from each and every one of you in the audience today. You have incredibly challenging jobs, which are some of the most creative, talented people I've ever had the opportunity to meet in my career. So if you've ever been on a research call with me or anyone on my team, thank you. You make our products so much better. Across all of these calls, there is one thing that I have heard consistently and that is that the complexity of managing today's tech ecosystem is absolutely overwhelming. The average enterprise today uses over 1,000 apps. That's an increase of 25% in just 2 years, and it's not just apps. Over 82% of companies use 3 or more cloud infrastructure providers. With all of these apps, platforms, users and devices, visibility and control can feel out of reach. Okay. Show of hands, how many of you have onboarded a new SaaS app to your organization in the last year? Okay, lots of hands, lots of hands. Now keep your hand up if the app you onboarded had built-in provisioning and deprovisioning, supported entitlements, had the ability to log users out automatically, okay, a lot fewer hands now. You're right. Most SaaS apps just don't have built-in identity security capabilities. And customers are telling me, you're building custom integrations that add complexity, cost and risk. At Okta, we're taking an active approach to help. We worked hand-in-hand with the most prominent SaaS companies in the industry to offer 125 enterprise security integrations. And these integrations are available today. Take a look at these names. This is just the beginning, though. There are over 30,000 SaaS apps out there. To bridge the gap, we need every single layer of the technology stack to speak a common language. We're leading the industry at Okta in the adoption of a new open identity security standard. It's called interoperability profile for the secure identity in the enterprise. Big name for a big standard, but I'll call it IPSIE. And it will provide a clear identity security blueprint for all enterprise technology. Any app in the future built to this standard will provide critical security capabilities from posture management and governance to privileged access and continuous authentication. Think about how much more secure our organizations will be and how much easier all of your jobs will be when every piece of tech in the ecosystem conforms to IPSIE. It's going to provide you the highest level of identity security before, during and after authentication. Before authentication, you'll be able to discover every part of your tech ecosystem, understand and remediate those risky identity misconfigurations. During authentication, you can enable phishing-resistant least privileged access controls for every user and nonhuman identity in your organization. And after authentication, you'll be able to continuously monitor every active session, listen for risk signals and terminate sessions with Universal Logout if a high-risk event occurs. And this isn't a far off dream. We are well on our way. So let's dive deeper into each of these phases and some of the things that how we are going to predict and some of the ways we are going to protect identity. Let's start with before authentication or the discovery phase. Our customers tell us that they want to be as proactive as possible. So even before someone attempts to log in, customers want holistic visibility across the entire identity environment. And that's because you can't protect what you can't see. Okta tackles this problem by helping customers discover identity posture risks, remediate them and implement secure access controls. Identity Security Posture Management is one of the newest products in Okta Suite. Identity Security Posture Management proactively discovers and prioritizes risks across your identity sources. I think about this as Okta's flashlight. It helps you see where risks and misconfigurations exist. And when you use ISPM as part of your unified solution, everything you uncover can be easily actioned across Okta. And one of the biggest misconfigurations coming to light recently is the sprawl of service accounts across SaaS apps. While we've come a long way in protecting users access to SaaS apps, there's a backdoor. Every SaaS app allows access to administrative and break class accounts. We hear from customers that these privileged accounts can easily fall out of the boundaries of traditional identity controls and go unprotected. That's why we've built secure SaaS service accounts. This is a new capability to discover, vault and manage these service accounts across your SaaS applications. Centralized control of these accounts helps eliminate standing privileges and reduces risk. Implementing security controls is step one, but maintaining that posture and visibility is quite challenging. And that's where new governance analyzer with Okta AI comes in. It leverages the power of your Okta ecosystem to help you make better governance decisions that lower your risk. And the best part is, it will learn and adapt as it's more widely adopted. The more you use it, the better it's going to get. It's kind of like your favorite pair of jeans. And that is all before anyone even logs in. Let's move on and look at the point of authentication. Our customers already use a wide range of high assurance phishing-resistant authenticators, such as FIDO2 web authent and smart cards. And of course, I'd be remiss if I didn't remind you all about Okta FastPass, which we built to be one of the most secure and user-friendly authenticators in the market. In fact, it is the fastest-growing authenticator among our customers. That user experience is just so blazing fast and simple. Actually, recently, a customer deployed FastPass across their organization. And the employees were so impressed with the UX that they renamed it the new super awesome Okta. And it's not just easy to use and super awesome, one of the other great things about FastPass is that it pulls device security signals to assess risk. And with advanced posture checks, we are further deepening the relationship between Okta and all your devices. You can now assess device security in real time and enforce deeper controls. For example, you can ensure that a device has ransomware checks enabled and deny access if not. These comprehensive posture signals can be gathered from any Windows or Mac OS device, managed or unmanaged. And once we've reduced risks inherent to the device itself, what about that authentication event, that's where Okta device access comes in. When a customer uses Okta device access, they enable a modern passwordless experience. Every sign-in attempt, from when you first sign in to a computer to when you open a new app, is protected by Okta. And today, we're enhancing this experience with a new capability called Extended Device Single Sign-on. You'll get stronger security and a smoother experience for your users. That's because the Okta session is tied to a hardware protected key on the device and it can't be replayed anywhere else. It also makes life easier for your users because after logging into their device with Okta, they can seamlessly access downstream applications with fewer prompts. And Okta is still reevaluating risk signals at every app access during the active session. Okay. So far, we've talked about secure policies, secure access controls, securing access to and from devices, but now let's talk about people. Social engineering and in particular, identity fraud are becoming an even bigger threat to our customers. With deep fake attacks getting more sophisticated and widespread, it is clear we are going to need a stronger way to validate that people are who they say they are. And that's why we're introducing out-of-the-box integrations for identity verification. We're building integrations with leading identity verification providers to give you flexibility and choice. And don't worry, I'll be sure to share this with our marketing team to keep Arnab and his corporate card and his anchovies very, very safe. Our integration with Persona is now available in early access. Integrations with CLEAR, Incode and on FIDO are also coming soon. Now as you know, identity security doesn't stop once a user is logged in. We need to continuously monitor for threats and respond rapidly when they're detected. So let's talk detection. Analysts call this identity threat detection and response. It's basically the ability to safeguard users during an active session. And this is where identity threat protection with Okta AI really shines. With deep integrations into your security stack, it continuously evaluates risk and allows you to automatically take certain actions like Universal Logout to contain threats. And we're expanding it with even more integrations like app Omni, CrowdStrike, Workspace ONE to further connect with the security tooling that you already own. For universal Logout, we're adding support for Cerby, which can extend protection to even more applications. And not only that, every app that's built with Okta's Customer Identity Cloud platform, we'll have support for Universal Logout. Take a look at all these names. As every app adopts the IPSIE standard, Okta will become the easiest, most effective solution for identity threat detection and response. As you can see, we have been busy. And it is one thing to talk about all of this, but let's see it in action. Please welcome to the stage my colleagues, Jamie Fitzgerald and Anna Simmons.

Unknown Executive

executive
#125

Thank you, Kristen. Now as an admin, let's dive into how Okta's unified identity security works in real-world scenarios, as Kristen said, before, during and after authentication. Now first, we'll see how Okta can -- discovers and remediates identity risk before authentication with Okta Identity Security Posture Management or ISPM. Now ISPM integrates with top identity providers, cloud infrastructure, SaaS applications to prioritize critical identity risk so we can focus on the most urgent issues. So for example, what we can see here is a number of global admin accounts without MFA in Salesforce created directly in the app and thus, bypassing Okta's identity controls. ISPM proactively and continuously monitors and can remediate threats and risks just like this. Now if I click on the Resolve tab, it reveals that ISPM automatically added these accounts to secure Salesforce admin group in Okta. And if I navigate to Okta's admin console, we can see that these accounts are now part of the Salesforce admin group. And if we look at the existing authentication policy for Salesforce administration, it shows that this admin group enforces phishing-resistant MFA such as Okta FastPass for secure access, mitigating the risks of direct access. Now speaking of enforcement, let's see how Okta enforces secure onboarding and authentication. Let's meet Anna, a new sales manager joining the company remotely. Now as part of her onboarding, Anna needs to enroll her mobile device's authenticator, but first, she must verify her identity.

Unknown Executive

executive
#126

I'm so excited to start at Mediax Media. And I received a welcome e-mail to my personal account with the secure activation link to start everything up. So let's go ahead and click this link. Okay. I'm going to need to download Okta Verify, I've already done that. And it looks like I'm going to need to verify my identity on my mobile device using Persona. That's really cool since it's going to ensure that only I can complete this process and access my account. So let's start the verification process. Okay. And when you need an ID, I'll use my driver's license. And I'll take a picture of the front of the license, done, and on the back, also done. That was easy. Let's see what's next. Okay. I'll need to complete a liveness check to prove my identity. So let's get started. You need to look left, right, done. And now I'm verified. Great. Let's finish setting up Okta Verify right now. I've got a few more clicks, continue, continue, allow push notifications, indefinitely FastPass. This is going to make it so easy for me to log into all my work apps without a password. Wait a second. Speaking of passwords, I just took that whole process without even a temporary password. I love working out at Mediax Media That was so convenient.

Unknown Executive

executive
#127

Now did you catch that? We just securely onboarded a new remote employee without a single password. And how about that slick ID verification process? It's brought to us by our partner, Persona, and includes multiple techniques to combat against deep fakes, like liveliness checks, camera attributes and real-time matches against official government databases. Now Anna can use this enrollment to securely enable Okta device access on her laptop. Then on a day-to-day basis with extended device single sign-on, Anna can access all of her Okta-protected apps seamlessly. By binding her session cryptographically to her device, we strengthened Zero Trust, stopped attackers from stealing the Okta session, all while reducing MFA prompts. Let's see how smoothly she can access her work apps.

Unknown Executive

executive
#128

I have a meeting coming up soon, so I better get logged into my laptops, so I can get everything I need open. Okay. First, I'm going to authenticate with Okta Verify, we'll use face ID, and done, I'm in. Now you might have missed it because that was so quick and seamless, but I just accessed my device without entering a password, thanks to Okta Device Access. And now that I'm securely logged into my laptop, I can open up my applications from my Okta dashboard. I'll log in to Gmail first. And I'm in, easy. Again, no password is needed. I'm signed in and ready to go. And I might even be early for my meeting now. At my old job, I had to unlock my laptop with one password and then type in a different user name and password for all of my apps, it was so annoying.

Unknown Executive

executive
#129

Pretty smooth. Now we know that different applications have different security requirements. And that's where advanced posture check comes in. We can check, enforce almost any attribute from Mac OS or Windows devices like app versions, processes running or security settings. The best part, we don't just block access. Admins can provide users with remediation steps to bring their devices back into compliance with your security requirements. Now earlier, Anna turned off a required setting controlled folder access when installing an application. This setting helps protect important folders from ransomware attacks and turning it off made her device noncompliant at our organization. Let's see what happens when she tries to access an app with her device in this state.

Unknown Executive

executive
#130

Well, now that I have a couple of minutes, I'm going to log into Workday so I can update my direct deposit information, Oh, it looks like my device doesn't meet security requirements. That's right, I turned off controlled folder access earlier. Unfortunately, this link -- this message from our IT team is giving me step-by-step instructions on how to fix this. So I'll just go into my settings. Let me find controlled folder access. I'll turn it back on. Yes. Now let me try to get into Workday again. Oh, I forgot. Workday is an app that has more sensitive data, so there's going to be an extra security check. I'll go ahead and provide this with a fingerprint scan. And I'm in, wow. I didn't even need to contact our help desk to resolve this. And even with that extra layer of security, it was still really easy for me to log in.

Unknown Executive

executive
#131

Now we just saw how advanced poster checks reduces security risk in real time and drives self-service remediation. Now when combined with identity threat protection, it becomes even more powerful as these device assurance checks can continue after authentication. That's because ITP continuously detects and responds to risks and threats. Now let's look at an unfortunately common scenario where Anna's session has been compromised by malware. Now with FastPass, ITP and Okta Device Access in place and working together, the attackers attempt to exploit the session any further is blocked immediately. First, FastPass by design prevents this session from being replayed from any unauthorized device. Then ITP takes it further triggering Universal Logout action across all supported apps. Finally, with Okta Device Access, we even log her out of her desktop to mitigate any malicious connectivity that may be taking place. Here's what it looks like to Anna.

Unknown Executive

executive
#132

Okay. Let me open up Zoho, so I can check how my pipeline is looking before my next call. Oh, wait a second. It says my Okta session was logged out due to a security alert. Wait, it looks like all of my applications are logged out. Oh my gosh, it looks like my device is being logged out too. It must be something serious. And I wonder what happened. Let me grab my phone, so I can call our help desk. It's great. They already wrote me a message to say that they're looking into it.

Unknown Executive

executive
#133

Now within identity threat protection, I can see exactly what happened. Now when I navigate to the risk tab on Anna's user profile, I can see that FastPass blocked this session token replay from an unrecognized device, providing immediate evidence of a session high jacking attempt. We also received an alert from Google SecOps, formerly known as Google Chronicle, that malware was detected on Anna's device. By combining Okta and third-party signals, we get a comprehensive view of the attack and can take further action. As we've seen, Okta protects at every stage while providing a seamless user experience. With that, take it back to Arnab. Thank you.

Arnab Bose

executive
#134

Thank you, Jamie and Anna. What an awesome demo, right? As you saw, our unified approach to identity security helps organizations raise their security bar and fought bad actors. But we are not on this journey alone. We believe in the power of collaboration and integration to push the boundaries of what's possible in identity security. That demo ended on a new shared signals framework integration with Google Chronicle. And now I'm excited to welcome to the stage the Head of Engineering for Google Chrome, Max Christoff. Welcome to Okta, Max.

Max Christoff

attendee
#135

Thanks so much. Thanks for having me. I am hyper-focused on security. And so whenever I get a chance to talk about that in an event like this, I'm all in. And I lead the engineering team for Chrome browser, as Arnab just mentioned, and happy to be here.

Unknown Executive

executive
#136

So one of the things we've been talking about throughout the session throughout the keynote has been securing identity before, during and after authentication. Okta is an approach with our product called Identity Threat Protection, but Google has also been investing in championing a new open standard called device bound session credentials for enterprise or DBSC, another acronym for us, Identity folk in the audience. How do you think Google Chrome is going to drive up adoption of this new standard? And how is it going to help?

Unknown Executive

executive
#137

Yes. By the way, great demo. And it's true. Session hijacking is a major threat. This is where we are seeing the attacks moving to and definitely something to be concerned about. And we took it upon ourselves to do something about that and most importantly, to do that in the standards-based approach. And that approach is Device Bound Session Credentials. So most web sessions set a cookie, right, after authentication happens, right? And if like me, you checked into the Caesars Palace, you presented your identity to the people at the front desk, you agreed to their daily resort fees, and you were presented with a freshly minted key card so you can get access to your hotel room. Great. But key cards, much like traditional web session cookies are vulnerable to threat, especially if you have an attacker with file system or network access, right? Even if you originally use 2-factor off to get there. So Device Bound Session Credentials fix that, right? They tie the session data to a particular device, making the stolen credentials useless on any other device. And it's like me going to my hotel room and not only does my key card work only on my door, but it only works if I'm the one holding the key card and presenting it. So we're excited about this, because this will enable much stronger security with minimal user friction. There's really no extra steps for users involved. This is just something that's going to be baked into Chrome. They won't even really know what's happening, and it's a big step for browser security. And by collaborating with Okta, I think we're really looking forward seeing this emerging standard rollout in the near future.

Unknown Attendee

attendee
#138

Absolutely. Yes I was going to add that as a product leader at Okta, I'm looking forward to the release of Device Bound Session Credentials next year sometime because once it start supporting Google applications, we'll also be able to opt in our Okta session cookies into that same protocol. So super excited. Just moving from Chrome and the browser to Google security strategy, so slightly in a slightly broader lens. Google has been leading the industry in Zero Trust with BeyondCorp for a long time now. What's next from the perspective of endpoint security or network security from Google?

Unknown Executive

executive
#139

Yes. I mean that's a great question, and we fundamentally agree that security starts with identity, and it doesn't end there, right? Networks and devices are still very much here. So we're very much focused on the future of endpoint security. Google's Zero Trust approach really did help redefine the landscape and help move the industry past VPNs. We don't use a single VPN anywhere at Google ourselves, and we want to take that same forward-looking approach to endpoint security. Chrome is really at the heart of that for us. Why Chrome? Well, Chrome has really become the operating system for work on all the devices, managed and unmanaged. It's where the traffic is happening, it's where work is happening. It's already being used on hundreds of millions of user desktops and mobile devices in enterprises every single day, and it's how people are accessing GenAI and everything new that's coming. And this gives us a major opportunity to really rethink endpoint security and just take it into the browser because it's already out there. So to do that, there are really a couple of offerings on top of the Chrome browser that you all know and love. There's Chrome Enterprise Core, which offers easy-to-use browser management through a cloud console, Google admin, no cost, no-brainer. There's basically no downside in using this. And that gives you access to see your extensions that are deployed, what's out there, manage your Chrome versions, update policies, all that good stuff. Chrome enterprise premium is something we launched this year, and it adds advanced features like data leakage controls in the browser, context to where access controls, a bunch of great stuff. Actually, speaking of great stuff, I just -- can I just share a quick data point that I heard about yesterday?

Unknown Attendee

attendee
#140

It's adoption data. I'm a product manager. I'd love to hear that.

Unknown Executive

executive
#141

Yes. So one of our customers actually of that Snap, yes, the Snap in Snapchat, if you have Teams in the audience, they might be using it right now. Snap implemented our data leakage controls and context of where access and almost overnight, they saw a 50% reduction in sensitive content being transferred out to a GenAI platform. So that was pretty cool. And above all -- thank you. Thank you. That's a good stat. Yes. So that made my night. I just want to stress as we make this easy. This is not like months of consulting time to set it up and manage. This is not a giant project. This is turning this on and getting started, and we're excited about partnering with leading security solutions like Okta and just building these integrations into the browser going forward. And specifically, our integration with Okta's Device Trust, really ensures that only secure devices can access the sensitive data, right now.

Unknown Attendee

attendee
#142

And we use that today actually in our own Okta and Okta deployment for the Chrome Enterprise. It's hooked up so that Chrome is the only browser we can use to access our enterprise systems and they're working really well. Let's maybe go to a slightly different topic, which is heterogeneous environments and systems. So we know our customers in the audience today, not all of them are using web-only apps. Some of them are using hybrid cloud environments, some of them have thick clients. What's your perspective on that sort of enterprise deployment?

Unknown Executive

executive
#143

I'm glad you asked about that because this is actually personal for me. I've been at Google for a while and Chrome for a while, but before that, I managed IT at Morgan Stanley, a Fortune 50 financial services company, and that was exactly our situation. And we had thick clients and thin clients and hybrid cloud. We had it at all, and it was a mess. And this pain is what I felt. And this has actually what drove me to come to Chrome, to come to Google because I've been in those shoes, and I think we can do better. So I'm really excited that Chrome and Okta have worked together to build a robust integrated solutions that provide just a lot of flexibility and deployment options and work for a wide range of tech stacks and environments. As much as I love all apps to be web apps is just we're not there yet and probably won't be for a little while. So as I mentioned, Chrome Enterprise premium launched earlier this year, and we have the data leakage protection in context of where access control that I mentioned and if you have Zero Trust deployed Secure Access Service Edge, it just integrates seamlessly into all of those things. So Chrome Enterprise, along with Okta and other partners really provides this OpenStack unified security framework. It's a wide variety of application needs, whether they're web-based or not.

Unknown Attendee

attendee
#144

Max, this really enforces our unified vision on identity security, connecting it up end-to-end and our deep integrations with vendors like Google and all of your security products. Thank you so much for joining us today here at Oktane and sharing that story. Please give Max a round of applause. Thank you.

Dave Gennarelli

executive
#145

Now let's take a look at how we are continuously improving the workforce Identity Cloud to be the world's most secure, trusted and reliable identity platform in the industry. Please welcome to the stage Abhi Sawant.

Abhi Sawant

executive
#146

So as you know, engineering is all about the art of making the impossible possible.

Arnab Bose

executive
#147

That's what I love about you, all the philosophy. Exactly.

Abhi Sawant

executive
#148

While I was backstage here, I couldn't but over here that you said you love anchovies. I had to kind of get my mind thinking about, wait, this got to be possible for me to do this. So I made some calls and my team delivered. And I'm glad to tell you that we got anchovies for you.

Arnab Bose

executive
#149

Wow. Check this out guys. Now this is the kind of fishing that I can get behind. Thank you, Abhi.

Abhi Sawant

executive
#150

Thank you, Arnab, and hello, everyone. As the CTO and Head of Engineering for the Workforce Identity Cloud, it's my team's responsibility to innovate and to build amazing products you've come to expect and sometimes anchovy. Seeing a hard work come to life here on stage and back in organization. That's the true highlight of my role. Thank you. Today, we've seen how Identity has become the backbone of security in every organization. Identity is not only the front door to your critical apps, it's also the core that helps you detect and respond to threats, discover and remediate risks and enforce access to your apps. With so much relying on the identity stack, identity is mission-critical. When systems fail, it's not -- when identities fail, it's not just an inconvenience to all of you and our customers, it can impact public safety, it can disrupt services, and it can cause major financial and regulatory fallout. This is why at Okta, downtime is never an option. We design resiliency that surpasses standard enterprise expectations. To give you some perspective, while another major identity provider had 10 hours worth of downtime in 2024, Okta has only experienced 31 minutes out of SLA across all cells. Let me repeat that. Okta has only seen 31 minutes out of SLA across all cells with the majority of the cells -- thank you. Majority of cells experiencing no downtime at all. That applause goes to my team, by the way. Let's see how we're delivering on this best-in-class resilience and scale that our customers need. We support 3 active availability zones in each of our cells or points of presence, designed to ensure uninterrupted service in case any of those zones fail. This architecture helps keep your identity systems available at all times. But resiliency is not only about availability, it's about rapid recovery when disruptions do happen. Today, we're introducing new self-service capabilities to our existing enhanced disaster solution. For those of you that were here last year, might feel a bit like deja vu, so let me explain this a little bit. We're introducing new self-service capabilities to our existing enhanced disaster solution that we introduced last year, and you're still confused and thinking, what does this mean? This gives you direct serve service control over the existing EDR solution so that in the event of a failure, you can initiate a failover to a read-only secondary site in under 5 minutes. That's less time than it takes to watch the Bellagio fountain show. Thank you. This helps keep our systems available at all times with your help. While we've made great strides to push industry-leading reliability, we're also investing to serve our customers that operate in highly regulated environments. Today, I'm glad to share that workflows, our no-code identity automation platform has gone to the FedRAMP high audit. Thank you. This milestone unlocks deep identity automation and orchestration flows for the U.S. public sector, helping agencies bolster security, reduce costs and improve operational efficiency, and it reflects our commitment to meeting the most rigorous security requirements. Our commitment to compliance though goes beyond just the United States. This is why we continue to expand our global compliance portfolio to address both regional and industry-specific needs. This includes new certifications like HDS in France for the health care data set or TSACs in Europe for the automotive industry or Spain's ENS high for the public sector. These certifications demonstrate Okta's dedication to supporting your operations across regions and sectors. We don't see compliance as a check box though. We see each new certification as a way to improve our products and how we operate across the board. For instance, instead of working your code and building new services to support new markets and customers when it's not needed, we make the rigorous standards of our most demanding customers, the baseline, for the entire platform, meaning our customers can seamlessly and confidently operate and expand across multiple markets securely. To sum it up, we're not just unifying your identity strategy. We're building a resilient and compliant foundation to support your business as security, growth, scale and transformation. And with that, I'd like to invite back to stage and hand it over to my good friend and Chief Pizza Officer, Arnab.

Arnab Bose

executive
#151

Thank you, Abhi. I want to quickly highlight some exciting news before we wrap up. Security isn't just about protecting employees, contractors and business partners. It's also super critical to secure customers and consumers. Today, we announced that we are accelerating investments in Okta's customer identity solution. And Oktane is back with ways to dive deeper into that product area. There are 6 CIS-focused sessions throughout Oktane, 2 demo booths and a dedicated road map session tomorrow and Thursday. Please check them out to learn more about how we are reinvesting in CIS. From customers to workforces in this fragmented digital world, identity is the thread that keeps your business safe. Here is what I'd like you to remember from today's session. First, Okta provides a unified approach to protect against identity attacks during -- before, during and after authentication. Second, we've built deep first-party integrations with leading enterprises to streamline secure access across all of your applications in your technology stack. And most importantly, we're leading the industry by pushing forward this open standard called interoperability profile for secure identity in the enterprise or IPSE. This way, every app vendor and every organization can achieve end-to-end identity security before, during and after authentication. Over the next couple of days, I encourage you to dive deeper into the capabilities we've announced, join our breakout sessions, engage with our experts in the Expo Hall and connect with peers to share strategies. Thank you for joining us today, and please enjoy the rest of Oktane.

Dave Gennarelli

executive
#152

All right. Good afternoon, Oktane. Welcome back. How is the morning so far? Good. All right. Well, I hope you're enjoying the day so far in taking in all the customer stories and product announcements. Now did you catch our announcements earlier in Todd's keynote about our efforts to standardize identity security across the industry? It's a bold vision. It's a bold vision to bake security into every click. It's because identity is deeply integrated into almost everything we do daily, specifically customer identity. When done right, customer identity can make our lives easier from filling our shopping carts to taking care of our families to also these days, driving our cars. The crucial role identity plays in our lives is why Okta has made it our priority since day 1. And we've been pioneering identity for 16 years. Now when cloud apps gained popularity in 2009, we realized that identity would be the key to both growth and security. We built a developer-centric platform that made implementing authentication easier than ever through powerful developer tooling, such as SDKs, APIs, quick starts and documentation. And we introduced new ways to build security into applications. And today, we block more than 3 billion attacks every single month. And we've proven that you don't need to sacrifice security to create delightful experiences. And we do this across more than 10 billion monthly authentications. Yes, that's billion with a B. And since day 1, we've set the bar for what customer identity should look like. And thanks to all of you who have integrated our APIs and SDKs into your products. It's because of your partnership and trust in us, we are by far the most used identity technology amongst developers today. Now we live in a world with more competition than ever before. Consumers' cost of switching brands has never been lower and the attack surface is increasing at an alarming rate. And you're facing new challenges and opportunities, and today, it's building applications that leverage generative AI. Now in just a few years, generative AI has transformed from an experimental technology to one that every business, every one of you is eager to incorporate into your applications products and experiences. And budgets for GenAI are growing fast. Spending in this category is expected to increase from $20 billion this year to over $200 billion by the end of 2028. That's a 10x increase in just 4 short years. And a few weeks ago, Marc Benioff, CEO of Salesforce said he envisions 1 billion, 1 billion Salesforce AI agents will be in service by the end of next year. We are in for a few years of exponential growth. In the next decade, we believe we will see the rise of a huge AI agent ecosystem. Networks of interconnected AI programs that integrate our applications and act autonomously for us. Now you heard earlier, we're leading the effort to drive the interoperability profile for secure identity in the enterprise or IPSE and plan to extend these standards to the agent ecosystem as well. But first, we need to enable builders to securely integrate generative AI into other applications, making them both AI and enterprise-ready. This is where Okta can help. Security and identity are big reasons, AI applications and agents are not commonplace yet. Now to understand the identity requirements, you all need to securely build GenAI into your applications. We've been engaging with experts, experimenting and watching the industry very, very closely. And we've identified 4 critical requirements where identity is crucial. So let's take a look at each. First, user authentication remains essential. The agent or app needs to know who I am. So for example, a chatbot might need to display my chat history or know my age and country of residence to customize the replies. This requires some form of identification, which can be done with our authentication services. Second, I want AI agents to do things for me. This means AI agents must interact with other applications on my behalf. AI agents connect to far more applications than a typical web application, but agents don't need user interfaces, as they only need APIs. And as GenAI applications integrate with more products, calling APIs on behalf of those users will become critical. Third, AI agents may take more time to complete tasks or wait for complex conditions to be met. It might be minutes, might take hours or it could take days. Now users aren't necessarily going to wait that long. But these cases will become mainstream and will be implemented as asynchronous workflows with agents running in the background. And for these scenarios, humans will act as supervisors approving or rejecting actions went away from a chatbot. Fourth and finally, almost all GenAI apps feed information to AI models from multiple systems to implement retrieval augmented generation, also commonly known as RAG. Now to avoid sensitive information disclosure, all data fed into AI models to respond or act on behalf of a user must be data the user has permission to access. Simply put, we need to solve all 4 requirements to realize GenAI's full potential. So let's take a look at how Okta is solving for these requirements. Market Xero is a fictitious GenAI-powered application that allows you to trade stocks. So first, I'll ask Market Xero for ZICO's stock price. Now could this be a good investment? I'll ask for some analysis of the company's future. And Market Xero generates a forecast using RAG on public earnings documents. And to ensure that the documents used to generate answers are only documents that I have access to. Market Xero leverages Okta Fine Grain authorization or FGA. As a reminder, Okta FGA is authorization as a service that allows development teams to centralize authorization logic and implement it with granular control. Now in this case, Market Xero implements authorization per user at the individual document level. Now I'll go ahead and join the Market Xero newsletter. So analyst reports are included when I ask for a forecast. Now behind the scenes, this changes the documents I have access to. So now if I ask for the forecast, again, I get something a lot more valuable because I can now access more documents. Okta FGA handled the access permissions behind the scenes. Let me get back to my investment. Given those forecasts, I want to monitor ZICO's price to earnings ratio and purchase shares if it falls below $5. Now Market Xero can do a lot, but it can't quite tell the future yet. So this may take a day, a week or a month. And this is a good fit for the asynchronous workflows I mentioned earlier. So I'm asked to enroll to get notified whenever the condition is met. And now I complete the enrollment on my phone by scanning a QR code and boom, I am all set. Now let to keep up with ZICO, so I want to be reminded of upcoming events. So first, let's see what events are coming up. I connect my Google account and consent to give Market Xero access to my calendar, so it can call the Google Calendar API on my behalf. Now Market Xero adds these events to my calendar. The magic behind this is that it uses our third-party API's feature which allows agents to call APIs of services such as Google Calendar, GitHub, Box and many, many more on the user's behalf. Well, it looks like I just got an authentication request on my phone. Market Xero is asking me to approve buying 10 shares of Zico. Now earlier, we asked Market Xero to buy Zico shares if it reached a certain price to earnings ratio. It looks like the condition has been met. So let's go ahead and approve it. But how does this work behind the scenes? Market Xero is a demo application we built to show how GenAI-powered applications can offer superior user experiences while adhering to identity best practices. Now Market Xero leverages our async authentication capability to implement on-demand authentication at the time of purchase. Users can simply approve or deny with a single tap. Now as async workflows become prevalent in GenAI apps, async authentication is required to make these transactions secure, timely and user-friendly. Now this reference application is powered by AFF for GenAI built upon decades of experience in identity, in building for developers. It empowers application builders to securely leverage generative AI in their applications. Now earlier, I referenced 4 requirements critical to building GenAI into your applications. Auth for GenAI delivers features to address these requirements. And to make it even easier for you to integrate auth for GenAI into your applications, we're also collaborating with popular GenAI libraries and frameworks. We can't wait to see you integrate auth for GenAI into your applications. So sign up for early access, wait list today auth0.ai. Now we see a world where AI agents will directly interact with APIs, requiring products to be AI-ready. And enterprises will build APIs for existing products and all new products are going to launch with an API. So this means that agent identity and securing how developers and partners access your API will become more critical than ever. So we will make it easy for you to expose your APIs to developers and partners securely. Developer portal will allow you to offer a branded secure developer portal instantly. Let's take a look at what this would look like. Now My Learning Co is a B2B learning platform that uses task tracking systems to assign mandatory learning content to new employees. And recently, they decided to integrate Task Vantage, which is a new task tracking app. So Jane, a developer at My Learning Co needs to add support for their AI agent to integrate with Task Vantage. So she will go and navigate to developers at taskvantage.com on her browser to access the Task Vantage developer portal. She goes ahead and inputs her e-mail and because My Learning Co is a Task Vantage partner, she can use SSO with her work account. She lands on the My Learning Co team account and starts the process to create new agent credentials. Now these credentials will allow the agent to securely obtain tokens to call the Task Vantage API. Now to create the agent credentials, Jane fills in a friendly name for the agent, a description, and will go ahead and upload the agent certificate. Then Jane sets the API scopes for the agent, choosing only what it needs based on the principle of least privilege. Now with that, Jane can add support for Task Vantage in the My Learning Co agent code base. She goes to the developer portal integration guide and picks langchain, the GenAI library My Learning Co uses for their agent. She follows the guide and updates the code to have the My Learning Co agent obtain a token to call the Task Vantage API. And that's it. In the future, setting up AI agents identity and integrating it with your API is going to be that simple. With the developer portal, we aim to get your APIs AI ready. With Okta, it's possible. If you're interested in this capability, you can sign up for the waitlist at auth0.ai/devportal. Okay. So we've looked at some amazing things that we can do to help you get more out of AI. But these capabilities are impossible without strong and secure authentication as the foundation. To share our latest innovations in security for builders, please welcome our CTO of Customer Identity Cloud, Bhawna Singh to the stage.

Bhawna Singh

executive
#153

All right. Hello, everyone. Hope you're enjoying Oktane and with Okta, it's possible, right? And thank you, Shiv for walking us through some of these fantastic demos. I bet we all want to go and start building these on the dev portal, me too, but wait, right? Because we also have to talk about how to secure the whole application. And the good news is we are pretty good at that as well. Okta has been a leading identity provider for authentication and authorization for 16 years. And we are committed to continue leading the industry in the fight against identity attacks. Stronger security doesn't just start and end at the login box. It starts long before users reach it and of course, throughout their entire journey after. If you can't detect bots, suspicious IPs or stolen credentials that attackers can use during login, your setup is already vulnerable. A single account takeover may not see much, but just one of these vulnerabilities can make you a prime target for a large scale attack. And account takeover at scale, well, that usually makes headlines. So that's why we enable application builders to easily implement layered security measures from the get-go. And now with our new free and self-service plans, we will enable every application builder to easily build their application to be IPSE compliant and secure by default. What if your application suddenly becomes a global hit? Now that's a very good problem to have, right? And many of our GenAI customers have experienced this rapid growth and rely on Okta to manage it. We make it easy for B2B SaaS application companies to scale and become enterprise ready. A core security requirement for SaaS application and, of course, a key part of IPSE is single sign-on. While building Identity Solutions isn't your core business, your team is distracted from product innovation to manage these needs and, of course, standards. What if your developers could focus on creating competitive features instead of SSO integrations. With self-service sign-on, you can programmatically send your customers' IT administrators, a link to a setup wizard and allowing them to configure SSO on their own. Integrating SSO into your applications enhances your security posture and moves you closer to being IPSE compliant. We have explored exciting new capabilities that can transform your business efficiently and securely. So let's look at one of our customers' journey to see how Okta Customer Identity Cloud is driving real world success. [Presentation]

Bhawna Singh

executive
#154

I love that video. And of course, it is real to see sometimes some from video jump out in real life, isn't it? So let's make that happen. I couldn't be more excited to have Thomas Mueller-Lynch from Siemens join us today to discuss their identity journey. Please welcome to the stage, Thomas. Thank you for joining us, Tom. Thank you for the partnership.

Thomas Mueller-Lynch

attendee
#155

Yes. For sure. Do we going to sit here or...

Bhawna Singh

executive
#156

Thomas, we are engineers, no comfort for us.

Thomas Mueller-Lynch

attendee
#157

Okay. Yes. I'm used to that.

Bhawna Singh

executive
#158

So we all know, and we saw the Siemens video. It speaks to their vastness of course. And of course, the technology powerhouse you all are. We would love to hear and our audience would love to hear how customer identity has helped Siemens, of course, to centralize your identity, which was the core conversation that we heard in the video.

Thomas Mueller-Lynch

attendee
#159

Yes. Well, as you saw in the video, so Siemens consists of main -- 3 main business units, and we have thousands of applications. And we had in the past a super diverse infrastructure if it comes to identity. Everybody use their own stuff. And now with Siemens ID, which is the service name of our Okta installation, we were able to consolidate that a lot, which obviously raises security and has lots of other benefits coming with it.

Bhawna Singh

executive
#160

The other thing that we also heard is with hundreds of divisions and thousands of applications that you have, you were able to bring all of this together with a very lean team that you mentioned. So we would love to hear how lean this team is. And how that felt?

Thomas Mueller-Lynch

attendee
#161

Yes. Well, to be honest, in the meantime, we extended the team a bit. But as we started with Siemens ID, we started with 3 people. Three people choosing at the very beginning in a quite, I would still say smart setup based on delegation on a developer-focused setup. Now in the meantime, we extended because more and more application has been onboarded to the system. We are now talking about hub-and-spoke infrastructure with the main tenant and 800 subtenants with thousands of applications. So that is not possible anymore with the 3 people, but now we ended up it with 8 to 9 people and running the system there.

Bhawna Singh

executive
#162

I think that speaks to the fact, Wow, that's the 8 of mighty team. And that's what CIC provides. So thank you for sharing that. I think another very important point for our industry is security is top of mind for every organization. And I know in our conversation you mentioned this, too. But I'd love to hear how customer identity platform is providing that capability. And also, how is it bolstering your security vision?

Thomas Mueller-Lynch

attendee
#163

Absolutely. I mean, as we heard here in various keynotes and various presentations, I'm also a strong believer if you do identity, you do it in the best place, you're doing it centrally because then you can put governance on it. You can put -- you can implement something like Zero Trust and all these kind of things. And that helped us a lot with that central system where we can configure them on the main tenant, all the security features. At the same time, we also can delegate as much as we want to keep that lean team. And with that combination, we were able to improve cybersecurity, a lot identity security a lot. So compared to think about of the past where we had all these different isolated systems where everybody did whatever they thought that's right for them. Now we have a much, much better security posture.

Bhawna Singh

executive
#164

That's amazing to hear. And of course, our journey with Siemens has been of many years, not just for you. So it's been a great partnership, and I really appreciate you coming in on the stage sharing your story and of course, solidifying that partnership further. Thank you so much, Thomas.

Thomas Mueller-Lynch

attendee
#165

Thank you. Appreciate it.

Bhawna Singh

executive
#166

What an incredible story, and thank you for sharing it with us, Thomas. And of course, the whole Siemens team that came together to bring this story to life. By choosing the right identity partner, Siemens quickly adopted new capabilities like Passkeys actually and across thousands of applications and you heard from the leader himself with 8 engineers, right? And this story highlights that security couldn't sacrifice and should not sacrifice user experience. Today, even one extra click can cost you a customer. And let's look at the data itself, where customer acquisition costs have surged by 222% over the last decade. 73% of customers expect better personalization as technology advances and why shouldn't they? Winning customers and their wallets is becoming harder and more expensive and customer identity is a secret ingredient that helps you stay ahead of that competition. Why? Because every digital journey starts with identity. When done right, it's the key to the customer acquisition and retention. And when done poorly, it's like locking the door in front of a potential customer. because every -- okay. Just a quick clicker issue. All right, why shouldn't technology come in between. All right. All right. So let's take an example that we all must have experienced, as you all came here for the Oktane itself, which is many of us must have booked fly to get here and using the same application on different devices. From browsing on a phone to buying tickets on a computer to checking a bag at a kiosk. And of course, maybe even somewhere in between, you spoke to AI agent, right? We all expected a consistent, easy and secure experience. That is identity done right. That's how you keep bringing your customers coming back. And we empower developers to build this experience efficiently. Many of you embrace universal login over the years to customize the login experience for your applications. And now advanced customization for universal login gives you even more power to customize the sign-up and sign-in experience across every application, device and the whole digital journey. You can leverage application and user information to deliver multi-brand experience, run AB tests and integrate analytics, all the things to help you drive conversion and growth. But great experiences don't stop at the login box. They continue long after, whether your customers are making a purchase or updating an account information. Have you ever called a customer service line to make changes to your credit card account? I bet you have. And you're likely asked security questions to verify your identity and these questions can be outdated or stale, questions such as what's your favorite singer or your dream vacation? I try to use my best friend's name. And even that keeps changing. So it gets frustrating because it's outdated and to verify all -- to use all this information to verify your identity. So client initiated back channel authentication or CIBA, let's you securely verify a customer's identity behind the scene when accessing their account in such situations. With CIBA, you can send a push notification to the customer's device, allowing them to verify their identity with a single tap. No need for outdated security questions. So now let's look at how all of this comes to life. Samantha will be demoing as a developer at Pledge Rocket, a fictional crowd funding application for start-ups and nonprofit. Samantha take it away.

Unknown Attendee

attendee
#167

As a leading cloud funding platform, we at Pledge Rocket connect thousands of start-ups with donors. Let's look at how we use customer identity cloud to deliver exceptional digital experiences. Our customer, Connect Zero is one of our thousands of start-ups that need a single sign on to our platform, pledgerocket using their identity provider. Let's go into admin dashboard here. Okay. So we can use self-service single sign-on to easily enable Connect Zero to set this up on their own tenant. Let's go into self-service configuration down here. And we can see here, I've already created SSO profile for them. Now I'll go ahead and send Connect Zero a quick link to a wizard that guides on to the set up in just a few clicks. Okay. So first, Connect Zero can click get started, assign their identity provider and then go ahead and create an application for Pledge Rocket, our platform. Now to set up SSO, they can go ahead and configure the connection here, perform claims mapping and test the connection. Then finally, they can assign access. With self-service SSO, we at Pledge Rocket can save thousands of developer hours and reduce risk of human error. Let's see how this all benefits our Customer Connect Zero. Sarah just joined Connect Zero as a campaigns manager. She can seamlessly single sign-on to our platform using Connect Zero's identity provider. This way, she can start managing campaigns with us right away. Now let's go back into our admin dashboard and here, we can add extra security after log-in using highly regulated identity. I'll start off by going here into post login triggers. Here, I can set up strong customer authentication for sensitive customer interactions. I can use actions to only trigger this type of step-up MFA for high-risk transactions. Okay. Next, let's setup CIBA for our help center agents. With CIBA, our agents can quickly verify users by sending them a quick push authentication right to their device. To set up CIBA, let's go into the Pledge Rocket app configuration here. Scroll down to advanced settings and I'll turn on the CIBA grant types for authentication flows. Now we're ready to enable the CIBA APIs and SDKs to build an integration between our Pledge Rocket application and the customer identity cloud. I can also customize a CIBA user experience using our Pledge Rocket custom mobile app. Now let's see how this comes together to protect our end users. Michelle, the treasurer of our Customer Connect Zero, receives a fishing e-mail stimulating a bank transaction. She clicks the link, and she tries to login to this fake portal compromising her credentials. The attacker then quickly goes in with Michelle's credentials and initiates the money transfer, triggering to step of MFA to her phone that we just set up. Upon reviewing the transaction details, Michelle realizes this is a fraudulent transaction and hits decline. This immediately triggers our Pledge Rocket security policies, that logs Michelle out of the Pledge Rocket website and blocks her access. Just like that, a fraudulent transaction is prevented. Now let's help Michelle get back into her account. Our help center agent can send Michelle, a quick push authentication to her device using CIBA. Once verified, our agent can then go in and unlock Michelle's account and send her a quick passive reset e-mail link. Just like that, no security questions required and Michelle's securely back in within minutes. And there we have it. Customer Identity Cloud made it so easy for us to deliver secure and streamline user experiences quickly and efficiently. Now I welcome back to the stage, Shiv. Shiv, I see you're rocking in MLS Jersey. Are you headed to a soccer match after this or something?

Shiven Ramji

executive
#168

Sam, I have to get match ready for this next section because Major League Soccer is here with us to share how they're using Customer Identity Cloud to elevate the fan experience. So without further ado, please welcome Major League Soccer Chief Technology Officer, John Nicastro to the stage. John. Thank you for joining us, John. First off, congrats on the award. Yesterday, you won for customer experience.

John Nicastro

attendee
#169

Thank you very much.

Shiven Ramji

executive
#170

Appreciate it. So I know bringing Messi to the U.S. is a pivotal moment for Major League Soccer but that generated excitement but also brought lots of challenges for MLS. So can you talk a little bit about sort of what brought you to consider a customer identity solution?

John Nicastro

attendee
#171

Sure. By the way, I love how you brought in Messi right into the first question. Awesome, love that. Yes. Look, I think a dynamic player like Messi, and I'm a little biased here. So arguably, the best player in the history of the sport. It definitely brings about a new challenge for us in terms of scale. It's a factor there and with his global audience and his global followers. But I think our journey with Identity really started with us acknowledging that as a modern brand, we have to be there with our customers where they are digitally. And we have to foster direct relationships with our fans in order to foster and nurture growth. And so and if we take a step back, it was thinking about the immediacy of social media or the fact that brand loyalty today is built on user experience, all of those factors combined led us to really think about what we have to continue to foster this relationship directly with our fans, and we have to do it in the channels where they are and at the heart of that is Identity.

Shiven Ramji

executive
#172

Amazing. And you mentioned you had some challenges with your current solution. Well you had something in-house. Maybe can you tell us what were the -- like what were the important factors for you to consider when selecting a new vendor, a new provider?

John Nicastro

attendee
#173

A new vendor. Yes, I think there were a couple of things there. Number one was, I think with the vast landscape of digital today, integration and a platform that can integrate into all of our technology and our architecture was super important for us. So that was one. Number two, I think it was making sure that we could outsource the complete thing into managed services because we wanted to focus our workforce on the things that matter to us, which is building new fan experiences and working on the beautiful game. And I think the third was just the partnership, not a vendor relationship, but a true partner because for us -- and I remember the first dinner you and I met, we sat down within 20 minutes, we were writing down ideas in the back of a napkin, and it was absolutely super powerful to know that we had a partner who had the passion and the ambition to achieve the vision that we were after with digital.

Shiven Ramji

executive
#174

Amazing. Well, I know I got to see some experiences you're building, and I'm not sure you can share about all of those today, but I'd love for the audience to understand sort of what are your plans with Customer Identity Cloud today and maybe a little bit of a glimpse of the future?

John Nicastro

attendee
#175

Yes. Well, I think the common theme here has been security, and we have to continue to earn our fans' trust. And so making sure that we have a platform that is built by design with security, data privacy, all the kind of things that are super relevant for us. As far as the future is concerned, we're super excited about disrupting the way that we can digitally engage with our fans. And we're working on things, my engineers are somewhere in the audience, are not going to like this because I'm going to reveal some things, but it's Vegas, so why not. Sorry, guys. But one of the things that we're working on in the spirit of AI agents is we're working on things like how to bring new immersive experiences to our fans. So -- because we talk about personalization all the time, which is an absolute multiplier across everything we do. But we like to call it in terms of contextualization because in our community, there's the element of time. And these moments are super important for us, because this is where fans emotionally connect with our brand. So you could have a moment in a match, a moment in a tournament or perhaps that magical Messi dribble and we want our fans to be able to engage with that. So one of the things that we're prototyping that we at the All-Star I think we had a little bit of a prototype there where you can go and say, "Hey, capture that moment for me, show me 3 different angles. And in one of those, I want to see it through the eyes of the goalie. I want to see the play unfold as Messi was coming towards me. And click for that...

Shiven Ramji

executive
#176

I am not sure the goalies want to watch that, Messi coming towards them, but...

John Nicastro

attendee
#177

Yes. So I think moments like that will be really important for us so that you can put those in your favorites list and come back and relive that emotional connection, which is super engaging for our fans. And it's what they want, they desire. So.

Shiven Ramji

executive
#178

Amazing. Thank you so much, John, for joining us. Thank you for sharing the insights. And thank you for being a partner.

John Nicastro

attendee
#179

Absolutely. Thank you for having me.

Shiven Ramji

executive
#180

Thank you. Now I don't know about you, but I'm even more excited about my next MLS game. Now I'm wearing a Jersey today, and I didn't want you to miss out. So I've got a little surprise for everybody in the room. There are 10 golden tickets spread throughout the room here. So you can check under your seats and see if you're a lucky winner of your own Messi jersey. Oh, there we go. We have some winners. I see 2, 3. Amazing. All right. There are a lot of empty seats too, but you can scour them later. If you have a golden ticket, please meet us at the stage at the end of the keynote. Now we've covered a lot today. So let's recap. With the rise of an AI agent ecosystem opt for GenAI will help developers build GenAI applications securely. Agents will need to interact with APIs, and Okta will enable you to make your APIs AI-ready. And finally, we will empower developers to be IPSE compliant with out-of-the-box security. I can't wait to see what you all built with these new capabilities. Now you can start building today for free at auth0.com. Scan the QR code to the left to see the full list of all the announcements we made today and scan the QR code to the right of it to join our auth for GenAI waitlist. I also encourage you to join our road map and customer-led breakout sessions over the next 2 days for a closer look at customer identity. Thank you for your time, and I look forward to connecting with many of this week and enjoy the rest of Oktane.

Unknown Executive

executive
#181

That was an amazing keynote. I love how all these announcements today allow you, our customers, to focus on innovation and ensure your users are able to interact seamlessly with your products. And the best part security is baked into every click. Good afternoon, everyone, and thank you for tuning into our segment on the Okta Secure Identity Commitment. My name is Matt Emler, and I'm one of Okta's regional CSOs, and I'm joined by Mickey Young, the newest member of our federal security team. Mickey, you're joining at an interesting time. We just introduced our OSIC strategy this year. For those of you who are unfamiliar, OSIC is short for the Okta Secure Identity Commitment. This initiative was started at the beginning of our current fiscal year and accompanied the reorganization of Okta's priorities, which place security in the #1 position.

Unknown Attendee

attendee
#182

That's awesome, Matt. I actually remember just this morning at the keynote that Todd was talking about the 4 pillars of OSIC, which encompasses Okta's security strategy and commitment. Can you tell me a little bit more about it?

Unknown Executive

executive
#183

Yes. So the pillars of OSIC are investing in market-leading products and services, championing customer best practices, raising the bar for our industry and finally, hardening our own corporate infrastructure.

Unknown Attendee

attendee
#184

Okay. So you mentioned investing in market-leading products and services. Can you elaborate some more on this? And what does it actually mean for our customers?

Unknown Executive

executive
#185

Yes, of course. The first pillar is of a particular importance to our customers. Okta has long since been a leader in identity and access management, but it's often been relegated to the IT side of the house and not necessarily viewed as a security product despite the many security advantages it provides. With the Secure Identity Commitment, we've kicked off investment in adding more market-leading security features to our offerings.

Unknown Attendee

attendee
#186

That's all very cool, Matt. It's clear that Okta is very invested in being the world's most secure company. Can you share a bit more about what Okta is doing at home and the type of products we use to stay secure?

Unknown Executive

executive
#187

Yes. At Okta, we make use of our own products or what we call Okta on Okta. This means that as we add security features for our own use that are also being added to our commercial products and made available to our customers as well. Administrator session binding or blocking anonymizing VPNs are just some of the features that we've recently added, which our customers can take advantage of right now, just as we do here at Okta.

Unknown Attendee

attendee
#188

Got it. So that's all encompassing of Okta's first pillar of the Secure Identity Commitment. So what's our second pillar?

Unknown Executive

executive
#189

The second pillar championing customer best practices is a complement to everything from our first pillar. Okta wants the secure configuration to be the default configuration. Therefore, we're working on removing additional steps to make your Okta deployment more secure by configuring certain security features of the default configuration out of the box. For example, Okta now requires multi-factor authentication for administrators. This is no longer an optional configuration item. It is now a core part of setting up administrator accounts. We've also ensured the previously configurable admin session time outs are now aligned with the NIST AAL3 standards. The goal being to ensure that the security best practices are always part of the Okta default state.

Unknown Attendee

attendee
#190

All right, Matt. I've got a question for you. You talk a lot about customers and security best practices. As one of the examples you just mentioned is requiring all administrators to have MFA settings turned on. What are the top 3 things on your customer best practice list you can share with us today?

Unknown Executive

executive
#191

Yes. There's so many that come to mind. But if I had to focus on 3 things for this segment, I think some of the most important I would be enforcing MFA and specifically using fishing resistant MFA, trying to stay away from some of the older factors such as SMS and e-mail as methods; second, adopt lease privilege with custom admin roles and regularly review the admin logs. And finally, secure service accounts used to integrate with services with Okta and preferably use API service integrations such as [indiscernible] in lieu of regular user accounts.

Unknown Attendee

attendee
#192

That all makes sense. Those are great suggestions. And I actually think that segments real nicely into Okta's third pillar. Matt, can you tell me a little bit more about how we can raise the bar in the industry?

Unknown Executive

executive
#193

Absolutely. Our third pillar and perhaps one of my favorites here is raising the bar for our industry. Okta believes that as an identity leader, we have a responsibility to elevate our industry and advocate for enhanced standards and education across the identity market as a whole. We're playing a big part in shaping these standards, but this isn't any sort of Okta secret sauce. We're at a unique moment in time where new security features for identity are becoming possible for every SaaS application today, and Okta is examining what we can do to lift the security of the entire ecosystem. Additionally, with our Okta for good programs, we help fund the digital transformation of nonprofits and advance career pathways into tech.

Unknown Attendee

attendee
#194

So what are some ways we're helping shape these industry standards?

Unknown Executive

executive
#195

Okta is using various platforms in order to document best practice in the industry and promote features and standards that we believe will benefit the entire identity community. This could be something like driving the adoption of passwordless or being early adopters of new technology. Members of the security team and the regional CSOs in particular, help promote these things through webinars, media interviews and producing content for wide distribution to reach as many people as possible. So unfortunately, that's about all the time we have for this segment. We couldn't get to the fourth pillar, but if you would like to learn more about the Okta Secure Identity Commitment, please visit our website online. We'll make sure that the link is in the chat for you to review, and we hope you have a great rest of your time at Oktane.

Unknown Attendee

attendee
#196

Thank you.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Okta, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Okta, Inc. earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.