Okta Identity Engine release notes (Preview)

Generally Available

Version: 2026.09.0

Okta Integration Network MCP server registration

You can now add MCP servers from an Okta Integration Network catalog entry, without entering its connection details manually. See Add an MCP server from the OIN catalog. This feature is following a slow rollout with preview deployment throughout mid-September, followed by production.

Dynamic Client Registration support for MCP server registration

Admins can now select Dynamic Client Registration (DCR) when manually registering an MCP server. When you select this option, Okta automatically registers a client with the provider and populates the credentials. See Manually add MCP servers. This feature is following a slow rollout with preview deployment throughout mid-September, followed by production.

Device assurance OS version update

The following OS versions are now supported in device assurance policies: * Android 14, 15, 16, 17 (2026-08-01)

New IP service categories for enhanced dynamic zones

Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • macOS 14.8.9
  • macOS 15.7.9
  • macOS 26.6.1
Okta On-Prem MFA agent version 1.8.7

This version includes security enhancements.

UI updates for AI agent client registration

On the AI agent > Client registration tab, the authentication methods are now displayed vertically and provide a Configure button. When you click Configure, you're directed to a configuration page for the authentication method.

Task count optimization

To improve performance in the Admin Console, the Tasks page now displays an approximate count of 999+ when a task contains more than 1,000 items.

Radius Agent version 2.27

This version includes internal improvements and fixes.

Copy email from-addresses to the default brand domain

You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • macOS (26.6.2)
  • iOS (26.6.1, 18.7.10)
  • Windows 10 builds (10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663)
  • Windows 11 builds (10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168)
Authentication requirement for AI agent app

When an AI agent is bound to an app, the User access tab now displays the authentication requirement for the app. It also provides a link to the app's Sign On tab where you can configure an authentication policy. 

JAMF Pro integration updates

The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM userName attribute.

Improved MCP server registration UI

MCP server registration has been updated with improved UI for scope handling and tool visibility.

Okta Provisioning Agent, version 3.3.1

Okta Provisioning Agent 3.3.1 is now available. This release updates the bundled JDK patch version and includes security enhancements. See Okta Provisioning Agent and SDK version history.

Provisioning for WordPress

Provisioning is now available for the WordPress integration. See Integrate WordPress with Okta

Provisioning for Ivanti

Provisioning is now available for the Ivanti integration. See Integrate Ivanti with Okta.

Provisioning for Progress Chef

Provisioning is now available for the Progress Chef integration. See Integrate Progress Chef with Okta.

SAP Connector

The SAP integration has been migrated to use the SCIM 2.0 API, and the connector's internal HTTP helper has been updated to support this standard.

DBSSO device probing improvement

DBSSO now relies on the device-registered conditions that are configured in an app's sign-on policy instead of using org-wide probing methods.

Remote Desktop detection

Admins can now detect and control access from remote desktops using a new REMOTE_DESKTOP IP service category in Enhanced Dynamic Network Zones. Admins can include or exclude REMOTE_DESKTOP when configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these networks. See Supported IP service categories.

Passkey enrollment promotion prompt

You can now configure a passkey enrollment promotion nudge that prompts end users to enroll a passkey authenticator when they sign in. The nudge applies only when the passkey authenticator is optional, and users who skip it can still sign in with another authenticator. You can control how often the prompt reappears and how many times a user can skip it before Okta stops showing it. See Create an authenticator enrollment policy.

Email notifications for disrupted AD and LDAP agents

System email notifications now include options for Active Directory and LDAP agent disruption and recovery. Admins can enable notifications in the Admin Console to receive email alerts when an agent disrupts and recovers.

Provisioning for Vercel

Provisioning is now available for the Vercel integration. See Integrate Vercel with Okta

Increased Access Request limit

The following Access Request limits have been increased:

  • Users per task or question: 25 (previously 10)
  • Entitlement bundles in an access level condition: 1,000 (previously 100)
  • Groups in an access level condition: 1,000 (previously 500)
  • Request type configuration lists per org: 250 (previously 100)
  • Request types per org: 750 (previously 500)
Tool discovery for MCP servers

When you register an MCP server, you can now test your credentials and discover its available tools. This ensures your connections are fully verified and lets you view the MCP server's capabilities. See Add MCP servers.

Platform SSO password integration with Device-Bound SSO

The Platform SSO password authentication method now integrates with Device-Bound SSO. When a user signs in at the macOS sign-in window, Okta verifies the password factor and creates a device-bound session. Users can then access Okta-protected apps in their browser without additional password prompts. See Platform SSO for macOS and Configure device configuration profiles for PSSO using a generic MDM.

Secure Enclave key support for Platform SSO

Platform SSO now supports a Secure Enclave key-based authentication method that integrates with Device-Bound SSO. When a user authenticates at the macOS sign-in window with their password, the authentication unlocks a hardware-bound cryptographic key stored in the Secure Enclave. Okta uses the key to create a device-bound session that satisfies any authentication policy that requires Okta FastPass with user verification, without repeated MFA prompts. See Platform SSO for macOS and Configure device configuration profiles for Secure Enclave using a generic MDM.

Device-Bound Single Sign-On

Device-Bound Single Sign-On initiates a hardware-protected session for seamless access to apps after users sign in to Okta-joined macOS and Windows devices. This feature provides session replay protection and a streamlined authentication experience. See Device-Bound Single Sign-On.

PowerShell scripts for Active Directory

Admins can now execute custom PowerShell scripts in on-premises Active Directory environments using the Active Directory agent to support custom lifecycle management functionalities. After configuration, admins can invoke scripts through Okta Workflows using the Okta public API. See Enable and configure PowerShell script in Active Directory and Invoke a remote script on the AD agent.

Early Access

Desktop MFA Factor Discovery for Windows

Desktop MFA for Windows now shows users only the MFA factors they've enrolled, instead of a fixed list of all available factors. New users without an enrolled factor can sign in during their grace period to set up MFA, while existing users signing in on a new device must verify with an existing factor. See Enable Desktop MFA Factor Discovery.

Okta On-prem SCIM Server agent is now Okta On-prem SCIM agent

Okta On-prem SCIM Server agent has been replaced by Okta On-prem SCIM agent. This change reduces the number of dependencies and allows for new features to be implemented. See On-prem Connector for Generic Databases.

Realm assignment limit increase

The maximum number of realm assignments allowed per profile source has been increased from 30 to 100. This enables admins to scale user organization and management across a larger number of realms. See Realms.

NFC authenticator

Okta now supports an NFC authenticator as an authentication method for frontline workers signing in to Okta-protected apps on Windows desktop shared workstations. To authenticate, an end user taps their NFC badge on a reader and enters a PIN to meet MFA requirements, without needing a phone, password, or shared account. See NFC authenticator.

Entitlement import safeguards

Entitlement import safeguards prevent user imports from accidentally removing app roles or licenses when a user is unassigned from an app. Admins can configure safeguards per app using either percentage-based or absolute count thresholds, and optionally block imports that modify or delete entitlement schemas. See Import safeguards.

Applications page enhancements

The Applications page now provides options to filter apps by type and status, search apps by name or client ID, and view apps by last modified date.  You can also export apps to CSV to turn your filtered list into an audit-ready report. During Early Access, labelling uses IGA Governance Labels and is only available for OIG customers. See Search, filter, and export app integrations and Resource labels.

Low-Code Sign In Customization

Customizations are a key concern for enterprises. Few things have as much impact on customer trust as the look and feel of their site branding. It's how users know to trust the site and learn about new offerings. With Low-Code Sign In Customization, admins can customize the text, colors, and images of their Sign-In Widget without the need for complicated or risky changes using the code editor. A JSON templating language with syntax highlighting and suggestions enable admins to make visual changes to the sign-in page and Interstitial authentication to match their desired experience without changing a line of code. See Customize your sign-in page.

On-prem Connector for Generic Databases supports high availability using Unified OPS Agent

The On-prem Connector for Generic Databases now supports high availability, which lets you assign multiple Okta On-Premises SCIM Agents to a single app instance so that any available agent can service an import or provisioning operation. This removes the single point of failure for on-premises database integrations and keeps them running while an individual agent is offline or being upgraded. See On-prem Connector for Generic Databases.

On-prem Connector for Generic Databases supports incremental imports

The On-prem Connector for Generic Databases now supports incremental imports, which retrieves only the users and entitlement assignments that have changed since the last successful import, rather than the full dataset. This reduces import duration and database load for large-scale deployments. The source database must use soft deletes and maintain an automatically updated timestamp column. See On-prem Connector for Generic Databases.

Fixes

  • Push notifications for Okta Verify challenges during direct authentication sometimes failed with a direct_auth_policy_denied error when biometric verification wasn't enrolled. (OKTA-1099950)

  • Password policy errors related to breached credentials protection persisted after admins resolved the issues. (OKTA-1239168)

  • Some links on the Sign-In Help page didn't meet the minimum contrast ratio. (OKTA-1241201)

  • Newly imported Active Directory users couldn't activate their accounts through email links when out-of-band Okta Verify enrollment was enabled in the Okta account management policy. (OKTA-1250588)

  • When no passkeys were enrolled, the End-User Dashboard showed the security method label as Security Key or Biometric Authenticator instead of Passkey. (OKTA-1258336)

  • Some custom profile attributes were still visible in the UI after they were deleted by an admin.  (OKTA-1260654)

  • When using Okta as a certificate authority (CA) instead of a third-party CA, the Okta CA didn't permit device re-registration after the device was deleted from Okta. (OKTA-1261907)

  • For AI agents with user sign-on delegations, the deprecation banner on the User access tab displayed incorrect information. (OKTA-1262867)

  • Custom admin roles could generate a Desktop MFA recovery PIN for users who weren't in their resource group if they had the device level recovery PIN permission. (OKTA-1264620)

  • When the Flexible Okta Verify authenticator configuration was enabled, end users who signed in to RADIUS apps with Okta Verify - Push received an error. (OKTA-1265932)

Okta Integration Network

  • Harriet (SCIM) was updated. Learn more.

  • Your360 (OIDC) is now available. Learn more.

  • Your360 (SAML) is now available. Learn more.

  • Harriet (OIDC) was updated.

  • Sensor Tower (SCIM) is now available. Learn more.

  • Visily Lifecycle Management Connector By Redblock (SCIM) is now available. Learn more.

  • Instagram (SWA) was updated.

Preview org features

SAP SuccessFactors OAuth 2.0 with SAML Assertion

The SAP SuccessFactors app integration now supports OAuth 2.0 with SAML Assertion for enhanced API security. To ensure your provisioning and sync processes continue without interruption, you must migrate to this new authentication method before the SAP Basic Authentication deletion deadline on November 20, 2026. See Configure OAuth 2.0 with SAML for SAP SuccessFactors.

Workday supports incremental imports

Workday now has the ability to run immediate, incremental imports. Incremental imports are much faster than full imports. However, they don't detect when users only have changes to custom attributes, so you must periodically run a full import to capture these changes. See Incremental imports.

Same-device enrollment for Okta FastPass

On orgs with Okta FastPass, the Okta Verify enrollment process has been streamlined:

  • Users can initiate and complete enrollment on the device they're currently using. Previously, two different devices were required to set up an account.
  • Users no longer need to enter their org URL during enrollment.
  • The enrollment flow has fewer steps. This feature is supported on Android, iOS, and macOS devices.
Direct End-User Settings access

Users may now access their Settings page through a direct URL in addition to the End-User Dashboard. This feature provides convenience and security for users, gives admins greater flexibility when working with End-User Dashboard access control scenarios, and includes accessibility and UX improvements. See End-User Settings.

End-user setting for nicknaming factors

End users can now nickname their phone, WebAuthn, and Okta Verify factors. If they have enrolled multiple instances of a factor, giving nicknames helps them identify the factors quickly (for example, "My personal cellphone" or "My office MacBook TouchID"). See the end-user documentation. This is a self-service feature.

Descriptive System Log events

When Okta identifies a security threat, the resulting security.threat.detected System Log entry now provides a descriptive reason for the event. See System Log.

New flexible LDAP

A new LDAP schema allows flexibility by moving email to the custom schema and making first name, last name, username, and UID optional. This avoids error scenarios when an LDAP schema doesn't include specific attributes.

ThreatInsight coverage on core Okta API endpoints

Okta ThreatInsight coverage is now available for core Okta API endpoints:

Based on heuristics and machine learning models, Okta ThreatInsight maintains an evolving list of IP addresses that consistently show malicious activity across Okta's customer base. Requests from these bad IP addresses can be blocked or elevated for further analysis when Okta ThreatInsight is enabled for an Okta org. Previously, Okta ThreatInsight coverage only applied to Okta authentication endpoints (including enrollment and recovery endpoints). With this release, enhanced attack patterns are detected for authentication endpoints and limited attack patterns are also detected for non-authentication endpoints. There are no changes to the existing Okta ThreatInsight configuration. You can still enable Okta ThreatInsight with log and block mode, log mode, and exempt network zones. A new Negative IP Reputation reason is available for high security.threat.detected events. See System Log events for Okta ThreatInsight.