Okta Classic Engine release notes (Preview)
Generally Available
Version: 2026.09.0
- New IP service categories for enhanced dynamic zones
Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
- Okta On-Prem MFA agent version 1.8.7
This version includes security enhancements.
- Task count optimization
To improve performance in the Admin Console, the Tasks page now displays an approximate count of
999+when a task contains more than 1,000 items.- Radius Agent version 2.27
This version includes internal improvements and fixes.
- Copy email from-addresses to the default brand domain
You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.
- JAMF Pro integration updates
The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM
userNameattribute.- Okta Provisioning Agent, version 3.3.1
Okta Provisioning Agent 3.3.1 is now available. This release updates the bundled JDK patch version and includes security enhancements. See Okta Provisioning Agent and SDK version history.
- Provisioning for WordPress
Provisioning is now available for the WordPress integration. See Integrate WordPress with Okta.
- Provisioning for Ivanti
Provisioning is now available for the Ivanti integration. See Integrate Ivanti with Okta.
- Provisioning for Progress Chef
Provisioning is now available for the Progress Chef integration. See Integrate Progress Chef with Okta.
- SAP Connector
The SAP integration has been migrated to use the SCIM 2.0 API, and the connector's internal HTTP helper has been updated to support this standard.
- Remote Desktop detection
Admins can now detect and control access from remote desktops using a new
REMOTE_DESKTOPIP service category in Enhanced Dynamic Network Zones. Admins can include or excludeREMOTE_DESKTOPwhen configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these networks. See Supported IP service categories.- Email notifications for disrupted AD and LDAP agents
System email notifications now include options for Active Directory and LDAP agent disruption and recovery. Admins can enable notifications in the Admin Console to receive email alerts when an agent disrupts and recovers.
- Provisioning for Vercel
Provisioning is now available for the Vercel integration. See Integrate Vercel with Okta.
- Increased Access Request limit
The following Access Request limits have been increased:
- Users per task or question: 25 (previously 10)
- Entitlement bundles in an access level condition: 1,000 (previously 100)
- Groups in an access level condition: 1,000 (previously 500)
- Request type configuration lists per org: 250 (previously 100)
- Request types per org: 750 (previously 500)
- PowerShell scripts for Active Directory
Admins can now execute custom PowerShell scripts in on-premises Active Directory environments using the Active Directory agent to support custom lifecycle management functionalities. After configuration, admins can invoke scripts through Okta Workflows using the Okta public API. See Enable and configure PowerShell script in Active Directory and Invoke a remote script on the AD agent.
Early Access
- Okta On-prem SCIM Server agent is now Okta On-prem SCIM agent
Okta On-prem SCIM Server agent has been replaced by Okta On-prem SCIM agent. This change reduces the number of dependencies and allows for new features to be implemented. See On-prem Connector for Generic Databases.
- Entitlement import safeguards
Entitlement import safeguards prevent user imports from accidentally removing app roles or licenses when a user is unassigned from an app. Admins can configure safeguards per app using either percentage-based or absolute count thresholds, and optionally block imports that modify or delete entitlement schemas. See Import safeguards.
- Applications page enhancements
The Applications page now provides options to filter apps by type and status, search apps by name or client ID, and view apps by last modified date. You can also export apps to CSV to turn your filtered list into an audit-ready report. During Early Access, labelling uses IGA Governance Labels and is only available for OIG customers. See Search, filter, and export app integrations and Resource labels.
- On-prem Connector for Generic Databases supports high availability using Unified OPS Agent
The On-prem Connector for Generic Databases now supports high availability, which lets you assign multiple Okta On-Premises SCIM Agents to a single app instance so that any available agent can service an import or provisioning operation. This removes the single point of failure for on-premises database integrations and keeps them running while an individual agent is offline or being upgraded. See On-prem Connector for Generic Databases.
- On-prem Connector for Generic Databases supports incremental imports
The On-prem Connector for Generic Databases now supports incremental imports, which retrieves only the users and entitlement assignments that have changed since the last successful import, rather than the full dataset. This reduces import duration and database load for large-scale deployments. The source database must use soft deletes and maintain an automatically updated timestamp column. See On-prem Connector for Generic Databases.
Fixes
-
When an admin configured a user profile attribute as required while sourcing it from an external app, profile enrollment policies entered an unresolvable sign-in loop. (OKTA-1178953)
-
When an Active Directory import safeguard was triggered, Okta incorrectly sent email alerts to users who were no longer admins. (OKTA-1208675)
-
Password policy errors related to breached credentials protection persisted after admins resolved the issues. (OKTA-1239168)
-
Some custom profile attributes were still visible in the UI after they were deleted by an admin. (OKTA-1260654)
Okta Integration Network
-
Harriet (SCIM) was updated. Learn more.
-
Your360 (OIDC) is now available. Learn more.
-
Your360 (SAML) is now available. Learn more.
-
Harriet (OIDC) was updated.
-
Sensor Tower (SCIM) is now available. Learn more.
-
Visily Lifecycle Management Connector By Redblock (SCIM) is now available. Learn more.
-
Instagram (SWA) was updated.
Preview org features
- SAP SuccessFactors OAuth 2.0 with SAML Assertion
The SAP SuccessFactors app integration now supports OAuth 2.0 with SAML Assertion for enhanced API security. To ensure your provisioning and sync processes continue without interruption, you must migrate to this new authentication method before the SAP Basic Authentication deletion deadline on November 20, 2026. See Configure OAuth 2.0 with SAML for SAP SuccessFactors.
- Workday supports incremental imports
Workday now has the ability to run immediate, incremental imports. Incremental imports are much faster than full imports. However, they don't detect when users only have changes to custom attributes, so you must periodically run a full import to capture these changes. See Incremental imports.
- Descriptive System Log events
When Okta identifies a security threat, the resulting
security.threat.detectedSystem Log entry now provides a descriptive reason for the event. See System Log.- New flexible LDAP
A new LDAP schema allows flexibility by moving email to the custom schema and making first name, last name, username, and UID optional. This avoids error scenarios when an LDAP schema doesn't include specific attributes.
- ThreatInsight coverage on core Okta API endpoints
Okta ThreatInsight coverage is now available for core Okta API endpoints:
Based on heuristics and machine learning models, Okta ThreatInsight maintains an evolving list of IP addresses that consistently show malicious activity across Okta's customer base. Requests from these bad IP addresses can be blocked or elevated for further analysis when Okta ThreatInsight is enabled for an Okta org. Previously, Okta ThreatInsight coverage only applied to Okta authentication endpoints (including enrollment and recovery endpoints). With this release, enhanced attack patterns are detected for authentication endpoints and limited attack patterns are also detected for non-authentication endpoints. There are no changes to the existing Okta ThreatInsight configuration. You can still enable Okta ThreatInsight with log and block mode, log mode, and exempt network zones. A new
Negative IP Reputationreason is available for highsecurity.threat.detectedevents. See System Log events for Okta ThreatInsight.