Okta Classic Engine release notes (Production)

Generally Available

Version: 2026.09.0

New IP service categories for enhanced dynamic zones

Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

Okta On-Prem MFA agent version 1.8.7

This version includes security enhancements.

Radius Agent version 2.27

This version includes internal improvements and fixes.

JA4 TLS fingerprinting

Okta now captures JA4 TLS client fingerprints across Syslog event types (securityContext.tlsFingerprint.ja4 pr), instead of just a curated subset. This includes telephony events (for example, OTP/SMS delivery) along with sign-in, auth, and token events. This provides customers and Okta's security teams with fingerprint-level visibility to spot bot traffic, toll fraud, and other TLS-based attack patterns that IP/user-agent signals miss on their own.

This is not yet available for orgs on custom-hosted domains.

Enhanced import monitoring with real-time updates

You can now view real-time progress for imports from the Import Monitoring dashboard. This provides greater visibility into the current status of in-progress imports such as the number of data chunks currently being processed.

Copy email from-addresses to the default brand domain

You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.

JAMF Pro integration updates

The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM userName attribute.

Provisioning for WordPress

Provisioning is now available for the WordPress integration. See Integrate WordPress with Okta

Provisioning for Ivanti

Provisioning is now available for the Ivanti integration. See Integrate Ivanti with Okta.

Provisioning for Progress Chef

Provisioning is now available for the Progress Chef integration. See Integrate Progress Chef with Okta.

SAP Connector

The SAP integration has been migrated to use the SCIM 2.0 API, and the connector's internal HTTP helper has been updated to support this standard.

Remote Desktop detection

Admins can now detect and control access from remote desktops using a new REMOTE_DESKTOP IP service category in Enhanced Dynamic Network Zones. Admins can include or exclude REMOTE_DESKTOP when configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these networks. See Supported IP service categories.

Email notifications for disrupted AD and LDAP agents

System email notifications now include options for Active Directory and LDAP agent disruption and recovery. Admins can enable notifications in the Admin Console to receive email alerts when an agent disrupts and recovers.

Provisioning for Vercel

Provisioning is now available for the Vercel integration. See Integrate Vercel with Okta

Increased Access Request limit

The following Access Request limits have been increased:

  • Users per task or question: 25 (previously 10)
  • Entitlement bundles in an access level condition: 1,000 (previously 100)
  • Groups in an access level condition: 1,000 (previously 500)
  • Request type configuration lists per org: 250 (previously 100)
  • Request types per org: 750 (previously 500)
Malware Proxy Detection

Admins can now detect and control access from known malware proxy networks using a new MALWARE_PROXIES IP service category in Enhanced Dynamic Network Zones. This category is powered by Okta's CyberDefense, covering proxy services associated with malware and botnet activity (including 911 S5, NSOCKS, iProxy, BHProxies, and others). Admins can include or exclude MALWARE_PROXIES when configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these proxy networks. See Supported IP service categories.

Okta Integration Wizard

Use the Okta Integration Wizard (OIW) to create and deploy custom app integrations in your Okta org. You can configure SSO, SCIM provisioning, Entitlement Management, Universal Logout, API service integration, and custom API Integration Actions capabilities for the app integration. You can use the app integration as a template to create multiple app instances in your org without reconfiguring each app instance. This helps you manage your custom integrations more efficiently and avoid workarounds for SCIM and custom Workflows connectors. See Okta Integration Wizard.

Okta Provisioning Agent, version 3.3.1

Okta Provisioning Agent 3.3.1 is now available. This release updates the bundled JDK patch version and includes security enhancements. See Okta Provisioning Agent and SDK version history.

Task count optimization

To improve performance in the Admin Console, the Tasks page now displays an approximate count of 999+ when a task contains more than 1,000 items.

Provisioning for Sophos Cloud

Provisioning is now available for the Sophos Cloud integration. See Integrate Sophos Cloud with Okta.

Early Access

Okta On-prem SCIM Server agent is now Okta On-prem SCIM agent

Okta On-prem SCIM Server agent has been replaced by Okta On-prem SCIM agent. This change reduces the number of dependencies and allows for new features to be implemented. See On-prem Connector for Generic Databases.

Entitlement import safeguards

Entitlement import safeguards prevent user imports from accidentally removing app roles or licenses when a user is unassigned from an app. Admins can configure safeguards per app using either percentage-based or absolute count thresholds, and optionally block imports that modify or delete entitlement schemas. See Import safeguards.

Applications page enhancements

The Applications page now provides options to filter apps by type and status, search apps by name or client ID, and view apps by last modified date.  You can also export apps to CSV to turn your filtered list into an audit-ready report. During Early Access, labelling uses IGA Governance Labels and is only available for OIG customers. See Search, filter, and export app integrations and Resource labels.

On-prem Connector for Generic Databases supports high availability using Unified OPS Agent

The On-prem Connector for Generic Databases now supports high availability, which lets you assign multiple Okta On-Premises SCIM Agents to a single app instance so that any available agent can service an import or provisioning operation. This removes the single point of failure for on-premises database integrations and keeps them running while an individual agent is offline or being upgraded. See On-prem Connector for Generic Databases.

On-prem Connector for Generic Databases supports incremental imports

The On-prem Connector for Generic Databases now supports incremental imports, which retrieves only the users and entitlement assignments that have changed since the last successful import, rather than the full dataset. This reduces import duration and database load for large-scale deployments. The source database must use soft deletes and maintain an automatically updated timestamp column. See On-prem Connector for Generic Databases.

Fixes

  • When an admin configured a user profile attribute as required while sourcing it from an external app, profile enrollment policies entered an unresolvable sign-in loop. (OKTA-1178953)

  • When an Active Directory import safeguard was triggered, Okta incorrectly sent email alerts to users who were no longer admins. (OKTA-1208675)

  • Password policy errors related to breached credentials protection persisted after admins resolved the issues. (OKTA-1239168)

  • Some custom profile attributes were still visible in the UI after they were deleted by an admin.  (OKTA-1260654)

Okta Integration Network

  • Harriet (SCIM) was updated. Learn more.

  • Your360 (OIDC) is now available. Learn more.

  • Your360 (SAML) is now available. Learn more.

  • Harriet (OIDC) was updated.

  • Sensor Tower (SCIM) is now available. Learn more.

  • Visily Lifecycle Management Connector By Redblock (SCIM) is now available. Learn more.

  • Instagram (SWA) was updated.