Okta Classic Engine Preview release notes

Version 2026.41.0. Deployed on October 7, 2026.

Generally Available features

Workday incremental import enhancements

Workday incremental imports now support up to 45,000 changed workers in a single incremental import.

Radius Agent version 2.28

This version changes the default client access behavior. Starting with this version, you must configure a client IP allowlist for new installations to accept RADIUS connections. See Okta RADIUS Server agent version history.

Entitlement support for disconnected apps

Disconnected apps are apps that aren't LCM integrated within Okta. This feature allows you to use CSV files to import users and entitlements into Okta from disconnected apps. This enables consistent governance and compliance across all apps, including those not fully integrated with Okta.

Provisioning for Fleet End User Enrollment

Provisioning is now available for the Fleet End User Enrollment integration. See Integrate Fleet End User Enrollment with Okta.

Provisioning for Pipedrive

Provisioning is now available for the Pipedrive integration. See Integrate Pipedrive with Okta.

Office 365 import updates

Office 365 imports now skip groups with 4-byte UTF-8 characters, such as emojis, instead of failing the entire job. Remaining groups import successfully, and Okta logs failed group details in syslog for troubleshooting.

Zendesk app integration update

Okta's Zendesk app integration now uses OAuth 2.0 instead of Basic Authentication for provisioning. If you use Zendesk provisioning, re-authenticate your API connection in the Admin Console by April 29, 2027 to prevent provisioning failures. New Zendesk app instances require OAuth 2.0 beginning October 26, 2026. This change doesn't affect SSO. See Integrate Zendesk with Okta.

App branding migration

Currently, when you upgrade to Identity Engine, that upgrade happens for your entire org, at a global level. You must prepare all of your customizations and integrations for every app before upgrading your tenant and reconfigure your upgraded org. If anything goes wrong, the whole upgrade must be rolled back.

The app branding migration feature allows eligible orgs to stage, preview, and deploy Identity Engine on an app-by-app basis while preserving their Classic Engine customizations and brands. Upgrade your most important and high-traffic apps first and with confidence, while leaving less critical apps for a later time. If anything goes wrong, only the affected apps need to be rolled back. See App branding migration.

Early Access features

OIN Community Integrations

New apps often launch before Okta has an integration for them, forcing admins to delay rollout or run the app without single sign-on and automated provisioning. Community Integrations close that gap. Okta builds the integration from the application's public APIs and publishes it to the Okta Integration Network at no additional cost. A new integration starts as Community Preview, available to install and test in preview orgs. Once a customer has run it in their own production org, it becomes Community Verified and can be installed in any org. You get a missing integration to test within days, not months, and decide when it's ready for production based on your own testing. See Community integrations.

New System Log events for staging Access Certification campaigns

The System Log now logs the following events for staging Access Certification campaigns:

  • certification.campaign.stage.start: This event is logged when the staging process starts for a campaign.

  • certification.campaign.stage.end: This event is logged when the campaign staging process ends. The outcome.result field reports SUCCESS if the campaign snapshot is created successfully, or FAILURE if there were errors during the staging process.

See Event Types.

Incremental imports for Office 365 is EA in Preview

Admins can now schedule and run incremental imports for Microsoft Office 365 and Office 365 GCC High app integrations.

Fixes

  • When an import resumed after an entitlement unassignment interruption, the import matrix incorrectly displayed the updated user count as 0 instead of reflecting the actual processed users. (OKTA-1272163)

  • Some policy.rule.update events weren't displayed in the System Log. (OKTA-1273973)

  • When an admin removed an entitlement locally, role or resource set updates failed to sync. (OKTA-1289782)

Okta Integration Network

  • Aembit (OIDC) is now available. Learn more.

  • Carta (SWA) was updated.

  • Holistics (SAML) is now available. Learn more.

  • Holistics (SCIM) is now available. Learn more.

  • Mailzzy (OIDC) is now available. Learn more.

  • Mailzzy (SAML) is now available. Learn more.

  • Spacent (OIDC) is now available. Learn more.

  • YakChat (OIDC) has a new redirect URI.

  • Your360 AI Directory Lookup (API Service Integration) is now available. Learn more.

Documentation updates

Changes to Okta release version notation

Beginning in October, Okta release version notations are changing from year.month to year.week. For example, 2026.10.0 will become 2026.41.0, where 41 indicates the week of the year that the deployment occurs. More information is available in this knowledge base article.