Okta Classic Engine release notes (Preview)
Generally Available
Version: 2026.08.0
- Provisioning for Barracuda
Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.
- Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
- Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
- Provisioning for Toggl
Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.
- Provisioning for Moodle
Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.
- Provisioning for HERE
Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.
- Okta Provisioning Agent, version 3.3.0
Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.
- Okta Active Directory agent, version 3.23.0
This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.
- New Research Release lifecycle
A new Research Release lifecycle is now available, marked with a Research Release banner in Okta admin documentation and visible in the Admin Console under Settings > Features. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.
- Request subscriptions data export
To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.
Early Access
- Synchronize device data with Anything-as-a-Source
In addition to users and groups, Custom Identity Source integrations can now synchronize device data from a source of truth. Devices use a fixed set of attributes:
serialNumber,platform, anddisplayName. See Use Anything-as-a-Source.- New System Log events for bulk device changes
The following System Log events are now available for bulk device changes:
system.identity_sources.bulk_device_upsertsystem.identity_sources.bulk_device_delete
- Multiple audiences for custom authorization servers
Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.
Documentation updates
- Okta Engine version switcher on help.okta.com
You can now verify whether a topic on help.okta.com applies to Identity Engine or Classic Engine and switch directly to the equivalent page in one click. The switcher stays visible as you scroll through the page. If a topic is unique to one engine, a
No matching topic for [Identity/Classic] enginemessage appears.
Fixes
-
In Security > Identity Providers, the Reset Certificate Chain button for Smart Card identity providers was available for read-only admins. (OKTA-1205602)
-
The
user.authentication.ssoevent was missing from the System Log when SAML inline hooks threw 5xx errors. (OKTA-1223139) -
Some sign-in attempts that referenced an unresolved bookmark app link returned the wrong type of error message. (OKTA-1234441)
-
When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile. (OKTA-1235909)
Okta Integration Network
-
StackAdapt (OIDC) was updated. Learn More.
-
Clutch Security (API Service) was updated. Learn More.
-
X (Twitter) (SWA) was updated.
-
Mountain Goat is now available. Learn more.
-
Alpacon now supports Express Configuration.
-
Alpacon (OIDC) is now available. Learn more.
-
Finopz (OIDC) is now available. Learn more.
-
Skillcast (SAML) is now available. Learn more.
-
Skillcast (SCIM) is now available. Learn more.
2026.08.1: Update 1 started deployment on August 13
- New IP service categories for enhanced dynamic zones
Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
Fixes
-
User Import inline hooks called Okta Workflows endpoints faster than the allowed invocation limit, causing rate limit errors during user imports. (OKTA-1081065)
-
When an admin's password was reset, the Admin roles tab disappeared from the user profile page in the Admin Console. (OKTA-1184998)
-
When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile. (OKTA-1235909)
-
When the user interaction requirement for an Okta Account Management Policy rule was set to Any interaction, Okta incorrectly enforced it as if Require device passcode or biometric user verification was selected, which could block users from signing in. (OKTA-1245305)
Okta Integration Network
-
Airwallex (OIDC) is now available. Learn more.
-
Bold Group Stages (SAML) is now available. Learn more.
-
Gateco (SCIM) is now available. Learn more.
-
NewCore (API Service) was updated.
-
Orca Security (SAML) is now available. Learn more.
-
Orca Security (SCIM) is now available. Learn more.
-
Square (OIDC) is now available. Learn more.
-
Statsig Lifecycle Management Connector by Redblock (SCIM) is now available. Learn more.
-
Vimeo Lifecycle Management Connector by Redblock (SCIM) is now available. Learn more.
Preview org features
- Workday supports incremental imports
Workday now has the ability to run immediate, incremental imports. Incremental imports are much faster than full imports. However, they don't detect when users only have changes to custom attributes, so you must periodically run a full import to capture these changes. See Incremental imports.
- Descriptive System Log events
When Okta identifies a security threat, the resulting
security.threat.detectedSystem Log entry now provides a descriptive reason for the event. See System Log.- New flexible LDAP
A new LDAP schema allows flexibility by moving email to the custom schema and making first name, last name, username, and UID optional. This avoids error scenarios when an LDAP schema doesn't include specific attributes.
- ThreatInsight coverage on core Okta API endpoints
Okta ThreatInsight coverage is now available for core Okta API endpoints:
Based on heuristics and machine learning models, Okta ThreatInsight maintains an evolving list of IP addresses that consistently show malicious activity across Okta's customer base. Requests from these bad IP addresses can be blocked or elevated for further analysis when Okta ThreatInsight is enabled for an Okta org. Previously, Okta ThreatInsight coverage only applied to Okta authentication endpoints (including enrollment and recovery endpoints). With this release, enhanced attack patterns are detected for authentication endpoints and limited attack patterns are also detected for non-authentication endpoints. There are no changes to the existing Okta ThreatInsight configuration. You can still enable Okta ThreatInsight with log and block mode, log mode, and exempt network zones. A new
Negative IP Reputationreason is available for highsecurity.threat.detectedevents. See System Log events for Okta ThreatInsight.