Okta Identity Engine release notes (Preview)

Generally Available

Version: 2026.08.0

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • Android 13, 14, 15, 16 security patch 2026-01-05
Claude supports SAML 2.0 SSO

The Claude app integration now supports SAML 2.0 SSO. Orgs that are subscribed to Okta for AI Agents can continue using the integration to import Claude Managed Agents into Okta. See Integrate Claude with Okta.

Provisioning for Barracuda

Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.

Provisioning for Linear

Linear provisioning is now available. See Create Linear integration.

Provisioning for Appspace

Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.

Agent-to-agent audience update

The agent-to-agent server resource url (audience parameter) can now be a free-form string.

Provisioning for Toggl

Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.

Provisioning for Moodle

Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.

Provisioning for HERE

Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.

Editable issuer URL for AI agent resource connections

Now when you create a resource connection between an AI agent and an authorization server, you can modify the authorization server's issuer URL.

Skipped failed entries during AI agent import

Now when you import AI agents from a provider, Okta skips the failed entries and creates or updates the successful ones. 

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • Android 14, 15, 16, 17 (2026-07-01)
  • Windows 10 builds (10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548)
  • Windows 11 builds (10.0.22631.7376, 10.0.26100.8875, 10.0.26200.8875)
Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • macOS (26.6, 15.7.8, 14.8.8)
  • iOS (26.6)
Improved smart card enrollment

Users can now enroll a smart card even if the login attribute doesn't match the value mapped from the card. Previously, enrollment failed during dynamic matching or Just-In-Time provisioning because the login attribute was treated as restricted from updates. See Add a Smart Card identity provider.

Okta Provisioning Agent, version 3.3.0

Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.

Okta Active Directory agent, version 3.23.0

This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.

New Research Release lifecycle

A new Research Release lifecycle is now available, marked with a Research Release banner in Okta admin documentation and visible in the Admin Console under Settings > Features. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.

Improved system log events for IdP routing

System log events for IdP routing now include the target information from the IdP Discovery rule that matched, when available.

New minimum character length for AI agent names

AI agent names now must contain a minimum of three characters. 

Request subscriptions data export

To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.

Updated passkey enrollment screen

The passkey enrollment screen in the Sign-In Widget now includes updated copy and an informational image to help users understand what a passkey is before they enroll.

MCP Servers and Resource Servers moved to Applications and Resources

In the Admin Console, the MCP Servers and Resource Servers pages have moved from the Directory menu to the Applications and Resources menu.

Applications menu renamed to Applications and Resources

In the Admin Console, the Applications menu is now called Applications and Resources.

Early Access

Policy change management

Admins can create branches of their app sign-in policies to review and monitor the impact of changes before enforcing the policy for end users. This allows admins to draft policy changes, test them against real user traffic, and roll them out with confidence. See Manage app sign-in policy branches.

Identity verification with vendor-submitted integrations

Identity verification (IDV) vendors can now submit integrations through the Okta Integration Network. You can configure and apply these integrations to your authentication policies to verify user identities.

Import AI agents from Glean

You can now import and manage AI agents built in the Glean Agent Builder directly through Okta. See AI agent imports.

Okta Verify Device Posture Sensor Mode

Previously, enforcing device security posture created significant blind spots on shared devices because it required a single-user Okta FastPass enrollment. Okta Verify Sensor Mode resolves this issue by registering the app directly to the org, allowing context-aware Device Assurance policies to be instantly evaluated when the user signs in. This is especially valuable for frontline workers, as it guarantees comprehensive compliance for shared fleets and ensures that devices are healthy before access is ever granted. See Device Posture Sensor Mode.

Device Visibility feature for macOS and Windows

Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.

Removal of Cross App Access configuration using Managed Connection

The removal of the ability to configure cross app access from the Managed connection tab located on the app's profile page is scheduled for an upcoming release. When it's removed, your existing configurations will stop working. Reconfigure your connections from the Resource Server tab to avoid disruptions. See Connect AI agents to resources.

New System Log events for bulk device changes

The following System Log events are now available for bulk device changes:

  • system.identity_sources.bulk_device_upsert
  • system.identity_sources.bulk_device_delete
Device Visibility feature for macOS and Windows

Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.

Multiple audiences for custom authorization servers

Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.

Flexible Okta Verify authenticator configuration

Okta Verify is bundled into a single authenticator with org-wide settings, preventing you from configuring individual verification methods (Okta FastPass, Push notification, or TOTP) per group. This feature separates Okta Verify into distinct, method-specific authenticators, allowing you to roll out Okta FastPass gradually.

Passkey enrollment promotion prompt

You can now configure a passkey enrollment promotion nudge that prompts end users to enroll a passkey authenticator when they sign in. The nudge applies only when the passkey authenticator is optional, and users who skip it can still sign in with another authenticator. You can control how often the prompt reappears and how many times a user can skip it before Okta stops showing it. See Create an authenticator enrollment policy.

User identification policy

Admins can now create a user identification policy to control whether the Sign in with Okta FastPass button appears on an app-by-app basis, instead of relying on a single org-wide setting. This makes it easier to manage pilot groups during Okta FastPass rollouts and to tailor the sign-in experience for individual apps. See User identification policy.

Fixes

  • In Security > Identity Providers, the Reset Certificate Chain button for Smart Card identity providers was available for read-only admins. (OKTA-1205602)

  • The user.authentication.sso event was missing from the System Log when SAML inline hooks threw 5xx errors. (OKTA-1223139)

  • The OAuth secure token exchange (STS) fields were visible for resource server apps that don't support the STS protocol.  (OKTA-1226327)

  • Some sign-in attempts that referenced an unresolved bookmark app link returned the wrong type of error message. (OKTA-1234441)

  • When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile.  (OKTA-1235909)

Okta Integration Network

  • StackAdapt (OIDC) was updated. Learn More.

  • Clutch Security (API Service) was updated. Learn More.

  • X (Twitter) (SWA) was updated.

  • Mountain Goat is now available. Learn more.

  • Alpacon now supports Express Configuration.

  • Alpacon (OIDC) is now available. Learn more.

  • Finopz (OIDC) is now available. Learn more.

  • Skillcast (SAML) is now available. Learn more.

  • Skillcast (SCIM) is now available. Learn more.

Preview org features

Workday supports incremental imports

Workday now has the ability to run immediate, incremental imports. Incremental imports are much faster than full imports. However, they don't detect when users only have changes to custom attributes, so you must periodically run a full import to capture these changes. See Incremental imports.

Same-device enrollment for Okta FastPass

On orgs with Okta FastPass, the Okta Verify enrollment process has been streamlined:

  • Users can initiate and complete enrollment on the device they're currently using. Previously, two different devices were required to set up an account.
  • Users no longer need to enter their org URL during enrollment.
  • The enrollment flow has fewer steps. This feature is supported on Android, iOS, and macOS devices.
End-user setting for nicknaming factors

End users can now nickname their phone, WebAuthn, and Okta Verify factors. If they have enrolled multiple instances of a factor, giving nicknames helps them identify the factors quickly (for example, "My personal cellphone" or "My office MacBook TouchID"). See the end-user documentation. This is a self-service feature.

Descriptive System Log events

When Okta identifies a security threat, the resulting security.threat.detected System Log entry now provides a descriptive reason for the event. See System Log.

New flexible LDAP

A new LDAP schema allows flexibility by moving email to the custom schema and making first name, last name, username, and UID optional. This avoids error scenarios when an LDAP schema doesn't include specific attributes.

ThreatInsight coverage on core Okta API endpoints

Okta ThreatInsight coverage is now available for core Okta API endpoints:

Based on heuristics and machine learning models, Okta ThreatInsight maintains an evolving list of IP addresses that consistently show malicious activity across Okta's customer base. Requests from these bad IP addresses can be blocked or elevated for further analysis when Okta ThreatInsight is enabled for an Okta org. Previously, Okta ThreatInsight coverage only applied to Okta authentication endpoints (including enrollment and recovery endpoints). With this release, enhanced attack patterns are detected for authentication endpoints and limited attack patterns are also detected for non-authentication endpoints. There are no changes to the existing Okta ThreatInsight configuration. You can still enable Okta ThreatInsight with log and block mode, log mode, and exempt network zones. A new Negative IP Reputation reason is available for high security.threat.detected events. See System Log events for Okta ThreatInsight.

SSO apps dashboard widget

The new SSO apps widget displays the number of user sign-in events across each of your org's apps over a selected period of time. You can use it to see which apps are used most frequently and to easily monitor the authentication activity across your org.

Improvements to the self-service unlock process

Earlier versions of the self-service unlock (SSU) flow created unnecessary friction in the end user experience. The newly enhanced SSU feature introduces a seamless magic link experience in emails sent out to unlock accounts. Users no longer need to provide consent when using the same browser. In addition, after successfully unlocking their account, clicking the email magic link counts towards the app's assurance policy. After the assurance requirements are met, the user is signed directly in to the app.

Improvements to the self-service registration experience

Earlier versions of the self-service registration (SSR) flow used a complicated array of templates to send activation emails to end users. The simplified SSR flow reduces this to only two email templates with customized welcome messages. If your app requires immediate verification of the end user's email address, Okta uses the Registration - Activation template. This template includes a magic link for a smoother sign-in experience. If email verification isn't immediately required to sign in to the app, Okta uses the Registration - Email Verification template. This template includes a link for end users to complete email verification at any time after they successfully sign in to the app.