Okta Classic Engine release notes (Preview)

Generally Available

Version: 2026.08.0

Provisioning for Barracuda

Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.

Provisioning for Linear

Linear provisioning is now available. See Create Linear integration.

Provisioning for Appspace

Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.

Provisioning for Toggl

Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.

Provisioning for Moodle

Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.

Provisioning for HERE

Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.

Okta Provisioning Agent, version 3.3.0

Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.

Okta Active Directory agent, version 3.23.0

This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.

New Research Release lifecycle

A new Research Release lifecycle is now available, marked with a Research Release banner in Okta admin documentation and visible in the Admin Console under Settings > Features. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.

Request subscriptions data export

To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.

Early Access

New System Log events for bulk device changes

The following System Log events are now available for bulk device changes:

  • system.identity_sources.bulk_device_upsert
  • system.identity_sources.bulk_device_delete
Multiple audiences for custom authorization servers

Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.

Fixes

  • In Security > Identity Providers, the Reset Certificate Chain button for Smart Card identity providers was available for read-only admins. (OKTA-1205602)

  • The user.authentication.sso event was missing from the System Log when SAML inline hooks threw 5xx errors. (OKTA-1223139)

  • Some sign-in attempts that referenced an unresolved bookmark app link returned the wrong type of error message. (OKTA-1234441)

  • When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile.  (OKTA-1235909)

Okta Integration Network

  • StackAdapt (OIDC) was updated. Learn More.

  • Clutch Security (API Service) was updated. Learn More.

  • X (Twitter) (SWA) was updated.

  • Mountain Goat is now available. Learn more.

  • Alpacon now supports Express Configuration.

  • Alpacon (OIDC) is now available. Learn more.

  • Finopz (OIDC) is now available. Learn more.

  • Skillcast (SAML) is now available. Learn more.

  • Skillcast (SCIM) is now available. Learn more.

Preview org features

Workday supports incremental imports

Workday now has the ability to run immediate, incremental imports. Incremental imports are much faster than full imports. However, they don't detect when users only have changes to custom attributes, so you must periodically run a full import to capture these changes. See Incremental imports.

Descriptive System Log events

When Okta identifies a security threat, the resulting security.threat.detected System Log entry now provides a descriptive reason for the event. See System Log.

New flexible LDAP

A new LDAP schema allows flexibility by moving email to the custom schema and making first name, last name, username, and UID optional. This avoids error scenarios when an LDAP schema doesn't include specific attributes.

ThreatInsight coverage on core Okta API endpoints

Okta ThreatInsight coverage is now available for core Okta API endpoints:

Based on heuristics and machine learning models, Okta ThreatInsight maintains an evolving list of IP addresses that consistently show malicious activity across Okta's customer base. Requests from these bad IP addresses can be blocked or elevated for further analysis when Okta ThreatInsight is enabled for an Okta org. Previously, Okta ThreatInsight coverage only applied to Okta authentication endpoints (including enrollment and recovery endpoints). With this release, enhanced attack patterns are detected for authentication endpoints and limited attack patterns are also detected for non-authentication endpoints. There are no changes to the existing Okta ThreatInsight configuration. You can still enable Okta ThreatInsight with log and block mode, log mode, and exempt network zones. A new Negative IP Reputation reason is available for high security.threat.detected events. See System Log events for Okta ThreatInsight.

SSO apps dashboard widget

The new SSO apps widget displays the number of user sign-in events across each of your org's apps over a selected period of time. You can use it to see which apps are used most frequently and to easily monitor the authentication activity across your org.

Federation Broker Mode

The new Federation Broker Mode allows Okta SSO without the need to pre-assign apps to specific users. Access is managed only by the authentication policy and the authorization rules of each app. This mode can improve import performance and can be helpful for larger-scale orgs that manage many users and apps.

User Import Scheduling

When importing users from an app to Okta, you can now schedule imports to occur at hourly, daily, or weekly intervals. Scheduling imports at a time that is convenient for your org reduces the likelihood of service disruptions and eliminates the need to start imports manually. If an application allows incremental imports, you can create both full and incremental import schedules. This is a self-service feature.

Null values for SCIM provisioning

You can now submit null values for any attribute type to Okta when using SCIM provisioning. This change reduces the error messages customers receive and simplifies end user identity management.

LDAP admin password reset

For orgs integrated with LDAP, admins can now perform password resets for an active individual end user. See Reset a user password.

LDAP password reset option

You can now configure LDAP delegated authentication settings to allow users to reset their passwords. This change reduces the time needed for password management and allows users to reset their passwords quickly and easily. See Enable delegated authentication for LDAP.

Windows Device Registration Task, version 1.4.1

This release fixed the following issues:

  • If there was a space in the sAMAccountName, an error appeared when installing the Okta Device Registration task and the installation completed but didn't function.
  • An unknown publisher warning appeared when the Okta Device Registration MSI file was double-clicked.

Affected customers should uninstall the registration task and install 1.4.1 or later. See Enforce Okta Device Trust for managed Windows computers and Okta Device Trust for Windows Desktop Registration Task Version History.

Incremental Imports for CSV

Incremental imports improve performance by importing only users who were created, updated, or deleted since your last import. See Manage your CSV directory integration. Note that this feature is being re-released having previously being released to Production in 2020.09.0.

Password changed notification email

To eliminate unnecessary email notifications, the Password changed notification email setting is no longer enabled by default on new preview orgs. See Password changed notification for end users.

Office 365 Silent Activation

Using Okta as the Identity Provider, Okta Office 365 Silent Activation allows for a seamless experience for your Microsoft Office 365 end users accessing Office 365 apps on domain-joined shared Workstations or VDI environments. After your end users have signed in to a domain-joined Windows machine, no further activation steps are required. See Office 365 Silent Activation: New Implementations.

End-user Welcome emails localized

The ability to localize the Welcome email that Okta sends to new end users by referencing the users' default locale property is now Generally Available. See Configure general customization settings.

People page improvements

You can now filter the People page by user type. See Universal Directory custom user types known issues.

Early Access features, auto-enroll

You can now opt to auto-enroll in all Early Access features, instead of having to enable them as they become available.

Connecting Apps to Okta using the LDAP Interface

The LDAP Interface allows you to authenticate legacy LDAP apps to Universal Directory in the Cloud. With the LDAP Interface, authentication is done directly against Okta through LDAP, without the need for an on-premise LDAP server. In addition, the LDAP interface supports other LDAP functions like search.