Okta Classic Engine Early Access features
Early Access features across current and past releases.
Early Access features
- Okta On-prem SCIM Server agent is now Okta On-prem SCIM agent
Okta On-prem SCIM Server agent has been replaced by Okta On-prem SCIM agent. This change reduces the number of dependencies and allows for new features to be implemented. See On-prem Connector for Generic Databases.
- Entitlement import safeguards
Entitlement import safeguards prevent user imports from accidentally removing app roles or licenses when a user is unassigned from an app. Admins can configure safeguards per app using either percentage-based or absolute count thresholds, and optionally block imports that modify or delete entitlement schemas. See Import safeguards.
- On-premises connector for Generic Databases
The new on-premises connector for Generic Databases allows admins to manage users and entitlements in on-premises databases using the Okta On-Prem SCIM Server. This connector supports Oracle, MySQL, PostgreSQL, and Microsoft SQL Server. It enables orgs to apply governance features like Access Requests, Certifications, Lifecycle Management, and Entitlement Management to their database environments. See On-prem connector for generic databases.
- Applications page enhancements
The Applications page now provides options to filter apps by type and status, search apps by name or client ID, and view apps by last modified date. You can also export apps to CSV to turn your filtered list into an audit-ready report. During Early Access, labelling uses IGA Governance Labels and is only available for OIG customers. See Search, filter, and export app integrations and Resource labels.
- Multiple audiences for custom authorization servers
Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.
- New System Log events for bulk device changes
The following System Log events are now available for bulk device changes:
system.identity_sources.bulk_device_upsertsystem.identity_sources.bulk_device_delete
- Synchronize device data with Anything-as-a-Source
In addition to users and groups, Custom Identity Source integrations can now synchronize device data from a source of truth. Devices use a fixed set of attributes:
serialNumber,platform, anddisplayName. See Use Anything-as-a-Source.- New System Log events for privileged access database integrations
Two new System Log events,
pam.integration.createandpam.integration.delete, are now available for Okta Privileged Access database management. This enhancement allows admins to track when database integrations are created or deleted. See System Log.- Auditor mode for admin role assignments
A new Auditor (Read-Only) mode allows super admins to apply a read-only restriction to any individual or group admin assignment. This setting restricts admins to read-only access across the Admin Console and Okta APIs, except for Okta first-party apps. This feature provides auditors with system visibility while maintaining security transparency. See Auditor read-only mode.
- On-prem Connector for Generic Databases supports incremental imports
The On-prem Connector for Generic Databases now supports incremental imports, which retrieves only the users and entitlement assignments that have changed since the last successful import, rather than the full dataset. This reduces import duration and database load for large-scale deployments. The source database must use soft deletes and maintain an automatically updated timestamp column. See On-prem Connector for Generic Databases.
- IBM Db2 LUW support for On-premises Connector for Generic Databases
The On-premises Connector for Generic Databases now supports IBM Db2 LUW. This enables admins to manage users and entitlements in IBM Db2 LUW environments. See On-prem connector for generic databases.
- Improved DirSync-based imports
Optimize performance of AD DirSync-based imports by skipping unnecessary prechecks and downloading organizational units without using DirSync.
- On-premises connector for Generic Databases
The new on-premises connector for Generic Databases allows admins to manage users and entitlements in on-premises databases using the Okta On-Prem SCIM Server. This connector supports Oracle, MySQL, PostgreSQL, and Microsoft SQL Server. It enables orgs to apply governance features like Access Requests, Certifications, Lifecycle Management, and Entitlement Management to their database environments. See On-prem connector for generic databases.
- Breached credentials protection
Protect your org from the impact of credentials that have been compromised. If Okta determines that a username and password combination has been compromised after being compared to a third-party curated dataset, the protection response is customizable through password policies, including resetting the user's password, forcing a logout, or calling a delegated Workflow. See Breached credentials protection.
Breached credentials protection is now available for Federal customers.
- Governance for Workflows now available in EA
You can now use Okta Identity Governance to manage access to Workflows roles. This helps you ensure that access to Workflows is granted consistently and in compliance with your company's requirements. See Governance for Workflows.
- Multiple active IdP signing certificates
Okta now supports multiple active signing certificates for a single SAML identity provider (IdP), enabling seamless certificate rotation with zero downtime. Admins can upload up to two certificates per IdP connection. This improvement eliminates the need for tightly coordinated swaps with IdP partners and reduces the risk of authentication failures due to expired certificates. The feature is available for both the Admin Console and the IdP Certificates API.
- JSON Web Encryption of OIDC ID Tokens
You can now encrypt OIDC ID tokens for Okta-protected custom app integrations using JSON Web Encryption. See Encrypt OIDC ID tokens for app integrations.
- Enforce MFA for Identity Governance admin apps
The Enforce MFA for Identity Governance admin apps feature is no longer available as a self-service Early Access feature. Admins must contact Okta Support to enable or disable this feature. See Enable MFA for the Admin Console.