Okta Identity Engine release notes (Preview)

Generally Available

Version: 2026.09.0

Okta Integration Network MCP server registration

You can now add MCP servers from an Okta Integration Network catalog entry, without entering its connection details manually. See Add an MCP server from the OIN catalog. This feature is following a slow rollout with preview deployment throughout mid-September, followed by production.

Dynamic Client Registration support for MCP server registration

Admins can now select Dynamic Client Registration (DCR) when manually registering an MCP server. When you select this option, Okta automatically registers a client with the provider and populates the credentials. See Manually add MCP servers. This feature is following a slow rollout with preview deployment throughout mid-September, followed by production.

Device assurance OS version update

The following OS versions are now supported in device assurance policies: * Android 14, 15, 16, 17 (2026-08-01)

New IP service categories for enhanced dynamic zones

Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • macOS 14.8.9
  • macOS 15.7.9
  • macOS 26.6.1
Okta On-Prem MFA agent version 1.8.7

This version includes security enhancements.

UI updates for AI agent client registration

On the AI agent > Client registration tab, the authentication methods are now displayed vertically and provide a Configure button. When you click Configure, you're directed to a configuration page for the authentication method.

Task count optimization

To improve performance in the Admin Console, the Tasks page now displays an approximate count of 999+ when a task contains more than 1,000 items.

Radius Agent version 2.27

This version includes internal improvements and fixes.

Copy email from-addresses to the default brand domain

You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • macOS (26.6.2)
  • iOS (26.6.1, 18.7.10)
  • Windows 10 builds (10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663)
  • Windows 11 builds (10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168)
Authentication requirement for AI agent app

When an AI agent is bound to an app, the User access tab now displays the authentication requirement for the app. It also provides a link to the app's Sign On tab where you can configure an authentication policy. 

JAMF Pro integration updates

The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM userName attribute.

Improved MCP server registration UI

MCP server registration has been updated with improved UI for scope handling and tool visibility.

Okta Provisioning Agent, version 3.3.1

Okta Provisioning Agent 3.3.1 is now available. This release updates the bundled JDK patch version and includes security enhancements. See Okta Provisioning Agent and SDK version history.

Provisioning for WordPress

Provisioning is now available for the WordPress integration. See Integrate WordPress with Okta

Provisioning for Ivanti

Provisioning is now available for the Ivanti integration. See Integrate Ivanti with Okta.

Provisioning for Progress Chef

Provisioning is now available for the Progress Chef integration. See Integrate Progress Chef with Okta.

SAP Connector

The SAP integration has been migrated to use the SCIM 2.0 API, and the connector's internal HTTP helper has been updated to support this standard.

DBSSO device probing improvement

DBSSO now relies on the device-registered conditions that are configured in an app's sign-on policy instead of using org-wide probing methods.

Remote Desktop detection

Admins can now detect and control access from remote desktops using a new REMOTE_DESKTOP IP service category in Enhanced Dynamic Network Zones. Admins can include or exclude REMOTE_DESKTOP when configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these networks. See Supported IP service categories.

Passkey enrollment promotion prompt

You can now configure a passkey enrollment promotion nudge that prompts end users to enroll a passkey authenticator when they sign in. The nudge applies only when the passkey authenticator is optional, and users who skip it can still sign in with another authenticator. You can control how often the prompt reappears and how many times a user can skip it before Okta stops showing it. See Create an authenticator enrollment policy.

Email notifications for disrupted AD and LDAP agents

System email notifications now include options for Active Directory and LDAP agent disruption and recovery. Admins can enable notifications in the Admin Console to receive email alerts when an agent disrupts and recovers.

Provisioning for Vercel

Provisioning is now available for the Vercel integration. See Integrate Vercel with Okta

Increased Access Request limit

The following Access Request limits have been increased:

  • Users per task or question: 25 (previously 10)
  • Entitlement bundles in an access level condition: 1,000 (previously 100)
  • Groups in an access level condition: 1,000 (previously 500)
  • Request type configuration lists per org: 250 (previously 100)
  • Request types per org: 750 (previously 500)
Tool discovery for MCP servers

When you register an MCP server, you can now test your credentials and discover its available tools. This ensures your connections are fully verified and lets you view the MCP server's capabilities. See Add MCP servers.

Platform SSO password integration with Device-Bound SSO

The Platform SSO password authentication method now integrates with Device-Bound SSO. When a user signs in at the macOS sign-in window, Okta verifies the password factor and creates a device-bound session. Users can then access Okta-protected apps in their browser without additional password prompts. See Platform SSO for macOS and Configure device configuration profiles for PSSO using a generic MDM.

Secure Enclave key support for Platform SSO

Platform SSO now supports a Secure Enclave key-based authentication method that integrates with Device-Bound SSO. When a user authenticates at the macOS sign-in window with their password, the authentication unlocks a hardware-bound cryptographic key stored in the Secure Enclave. Okta uses the key to create a device-bound session that satisfies any authentication policy that requires Okta FastPass with user verification, without repeated MFA prompts. See Platform SSO for macOS and Configure device configuration profiles for Secure Enclave using a generic MDM.

Device-Bound Single Sign-On

Device-Bound Single Sign-On initiates a hardware-protected session for seamless access to apps after users sign in to Okta-joined macOS and Windows devices. This feature provides session replay protection and a streamlined authentication experience. See Device-Bound Single Sign-On.

PowerShell scripts for Active Directory

Admins can now execute custom PowerShell scripts in on-premises Active Directory environments using the Active Directory agent to support custom lifecycle management functionalities. After configuration, admins can invoke scripts through Okta Workflows using the Okta public API. See Enable and configure PowerShell script in Active Directory and Invoke a remote script on the AD agent.

Provisioning for Sophos Cloud

Provisioning is now available for the Sophos Cloud integration. See Integrate Sophos Cloud with Okta.

Early Access

Desktop MFA Factor Discovery for Windows

Desktop MFA for Windows now shows users only the MFA factors they've enrolled, instead of a fixed list of all available factors. New users without an enrolled factor can sign in during their grace period to set up MFA, while existing users signing in on a new device must verify with an existing factor. See Enable Desktop MFA Factor Discovery.

Okta On-prem SCIM Server agent is now Okta On-prem SCIM agent

Okta On-prem SCIM Server agent has been replaced by Okta On-prem SCIM agent. This change reduces the number of dependencies and allows for new features to be implemented. See On-prem Connector for Generic Databases.

Realm assignment limit increase

The maximum number of realm assignments allowed per profile source has been increased from 30 to 100. This enables admins to scale user organization and management across a larger number of realms. See Realms.

NFC authenticator

Okta now supports an NFC authenticator as an authentication method for frontline workers signing in to Okta-protected apps on Windows desktop shared workstations. To authenticate, an end user taps their NFC badge on a reader and enters a PIN to meet MFA requirements, without needing a phone, password, or shared account. See NFC authenticator.

Entitlement import safeguards

Entitlement import safeguards prevent user imports from accidentally removing app roles or licenses when a user is unassigned from an app. Admins can configure safeguards per app using either percentage-based or absolute count thresholds, and optionally block imports that modify or delete entitlement schemas. See Import safeguards.

Applications page enhancements

The Applications page now provides options to filter apps by type and status, search apps by name or client ID, and view apps by last modified date.  You can also export apps to CSV to turn your filtered list into an audit-ready report. During Early Access, labelling uses IGA Governance Labels and is only available for OIG customers. See Search, filter, and export app integrations and Resource labels.

Low-Code Sign In Customization

Customizations are a key concern for enterprises. Few things have as much impact on customer trust as the look and feel of their site branding. It's how users know to trust the site and learn about new offerings. With Low-Code Sign In Customization, admins can customize the text, colors, and images of their Sign-In Widget without the need for complicated or risky changes using the code editor. A JSON templating language with syntax highlighting and suggestions enable admins to make visual changes to the sign-in page and Interstitial authentication to match their desired experience without changing a line of code. See Customize your sign-in page.

On-prem Connector for Generic Databases supports high availability using Unified OPS Agent

The On-prem Connector for Generic Databases now supports high availability, which lets you assign multiple Okta On-Premises SCIM Agents to a single app instance so that any available agent can service an import or provisioning operation. This removes the single point of failure for on-premises database integrations and keeps them running while an individual agent is offline or being upgraded. See On-prem Connector for Generic Databases.

Okta Verify support for Linux

Okta Verify now supports Linux desktop devices, allowing admins to extend phishing-resistant hardware-backed Okta FastPass authentication to Linux users. This release provides official support for devices running Ubuntu 24.04 and 26.04. See Deploy Okta Verify to Linux devices.

On-prem Connector for Generic Databases supports incremental imports

The On-prem Connector for Generic Databases now supports incremental imports, which retrieves only the users and entitlement assignments that have changed since the last successful import, rather than the full dataset. This reduces import duration and database load for large-scale deployments. The source database must use soft deletes and maintain an automatically updated timestamp column. See On-prem Connector for Generic Databases.

Fixes

  • Push notifications for Okta Verify challenges during direct authentication sometimes failed with a direct_auth_policy_denied error when biometric verification wasn't enrolled. (OKTA-1099950)

  • Password policy errors related to breached credentials protection persisted after admins resolved the issues. (OKTA-1239168)

  • Some links on the Sign-In Help page didn't meet the minimum contrast ratio. (OKTA-1241201)

  • Newly imported Active Directory users couldn't activate their accounts through email links when out-of-band Okta Verify enrollment was enabled in the Okta account management policy. (OKTA-1250588)

  • When no passkeys were enrolled, the End-User Dashboard showed the security method label as Security Key or Biometric Authenticator instead of Passkey. (OKTA-1258336)

  • Some custom profile attributes were still visible in the UI after they were deleted by an admin.  (OKTA-1260654)

  • When using Okta as a certificate authority (CA) instead of a third-party CA, the Okta CA didn't permit device re-registration after the device was deleted from Okta. (OKTA-1261907)

  • For AI agents with user sign-on delegations, the deprecation banner on the User access tab displayed incorrect information. (OKTA-1262867)

  • Custom admin roles could generate a Desktop MFA recovery PIN for users who weren't in their resource group if they had the device level recovery PIN permission. (OKTA-1264620)

  • When the Flexible Okta Verify authenticator configuration was enabled, end users who signed in to RADIUS apps with Okta Verify - Push received an error. (OKTA-1265932)

Okta Integration Network

  • Harriet (SCIM) was updated. Learn more.

  • Your360 (OIDC) is now available. Learn more.

  • Your360 (SAML) is now available. Learn more.

  • Harriet (OIDC) was updated.

  • Sensor Tower (SCIM) is now available. Learn more.

  • Visily Lifecycle Management Connector By Redblock (SCIM) is now available. Learn more.

  • Instagram (SWA) was updated.

2026.09.1: Update 1 started deployment on September 17

UI update for MCP server scopes

Now when you add custom scopes to an MCP server, the list of scopes appears in a separate dialog. See Add an MCP server manually.

Automatic tasks and questions reassignment after a manager change

To prevent access requests from being blocked during organizational changes, Okta Access Requests now automatically reassigns pending manager tasks and manager questions to an employee's new manager whenever a manager change occurs. This automated reassignment ensures that approvals proceed without manual IT intervention or delays, even if the previous manager's account has already been deactivated. This is available for requests built with both request conditions and request types.

Requester timeline view

Requesters can now view a detailed status timeline of their request's tasks directly from the Okta Access Request app. This enhanced visibility allows requesters to easily track the progress of their requests, see who has approved individual tasks, and identify remaining tasks, helping users stay informed throughout the approval process and reducing unnecessary status inquiries. The timeline is available for requests built with access request conditions.

Fixes

  • When users updated the Okta Verify app on iOS devices, the System Log recorded multiple user.mfa.factor.update events within a single day. (OKTA-1215063)

  • Switching the Access Control option for a Password policy rule from Legacy to Authentication policy didn't override the legacy settings for additional authenticators. This caused users to be prompted to enroll in additional authenticators that weren't required. (OKTA-1220283)

  • Users who signed in with Okta FastPass and selected Stay signed in couldn't update their password when they clicked Edit Profile in the End-User Dashboard. (OKTA-1224212)

  • When users attempted to sign in with Okta FastPass on a shared device, no error message was shown to inform them that Okta FastPass wasn't available on shared devices. (OKTA-1237130)

  • When creating or updating a user identification policy, you could select only the first 20 network zones for the user identification policy rule. (OKTA-1259477)

  • After users signed out, clicking Sign in with NFC could become unresponsive while Okta Verify searched for an available instance, requiring users to try again. (OKTA-1265555)

  • When an admin begin a user import for a single service account without an Okta user object, the profile sync process incorrectly updated all users in the Active Directory instance. (OKTA-1267422)

  • When users with the Auditor (Read-Only) admin role attempted to authenticate using Okta Verify Push, approving the push prompt on their mobile device returned a "Failed to send push notification" error message. (OKTA-1268324)

  • Admins could remove an authorization server with active managed connections from an MCP server. (OKTA-1273048)

Okta Integration Network

  • Atomicwork (SAML) is now available. Learn more.

  • Cockroach Labs (SCIM) was updated with a new app logo.

  • Entrust IDV (IDV) is now available. Learn more.

  • MongoDB Atlas is now available in OIN with SCIM 2.0 Provisioning support, which automates user lifecycle and access management between Okta and MongoDB Atlas.

  • StitchOps (OIDC) is now available. Learn more.

Preview org features

Agent Gateway

Agent Gateway is an identity-native proxy that sits between AI agents and the enterprise tools that they call. It aggregates tools from multiple remote MCP servers behind a single Okta-secured endpoint, enforces identity and policy on every tool call, and produces a unified audit trail. See Agent Gateway.

CIMD for OIDC apps

You can now add Client ID Metadata Documents (CIMD) to OIDC app integrations so they can identify themselves to Okta. This eliminates the use of shared secrets and manually configured OAuth clients. Okta fetches an app's redirect URIs and other client details directly from the CIMD and creates the client automatically. See About Client ID Metadata Documents (CIMD).

User identification policy

Admins can now manage rules in the user identification policy to control whether the Sign in with Okta FastPass button appears on an app-by-app basis, instead of relying on a single org-wide setting. This makes it easier to manage pilot groups during Okta FastPass rollouts and to tailor the sign-in experience for individual apps. See Add a rule to a user identification policy.

SAP SuccessFactors OAuth 2.0 with SAML Assertion

The SAP SuccessFactors app integration now supports OAuth 2.0 with SAML Assertion for enhanced API security. To ensure your provisioning and sync processes continue without interruption, you must migrate to this new authentication method before the SAP Basic Authentication deletion deadline on November 20, 2026. See Configure OAuth 2.0 with SAML for SAP SuccessFactors.

Workday supports incremental imports

Workday now has the ability to run immediate, incremental imports. Incremental imports are much faster than full imports. However, they don't detect when users only have changes to custom attributes, so you must periodically run a full import to capture these changes. See Incremental imports.

Same-device enrollment for Okta FastPass

On orgs with Okta FastPass, the Okta Verify enrollment process has been streamlined:

  • Users can initiate and complete enrollment on the device they're currently using. Previously, two different devices were required to set up an account.
  • Users no longer need to enter their org URL during enrollment.
  • The enrollment flow has fewer steps. This feature is supported on Android, iOS, and macOS devices.
Direct End-User Settings access

Users may now access their Settings page through a direct URL in addition to the End-User Dashboard. This feature provides convenience and security for users, gives admins greater flexibility when working with End-User Dashboard access control scenarios, and includes accessibility and UX improvements. See End-User Settings.

End-user setting for nicknaming factors

End users can now nickname their phone, WebAuthn, and Okta Verify factors. If they have enrolled multiple instances of a factor, giving nicknames helps them identify the factors quickly (for example, "My personal cellphone" or "My office MacBook TouchID"). See the end-user documentation. This is a self-service feature.

Descriptive System Log events

When Okta identifies a security threat, the resulting security.threat.detected System Log entry now provides a descriptive reason for the event. See System Log.

New flexible LDAP

A new LDAP schema allows flexibility by moving email to the custom schema and making first name, last name, username, and UID optional. This avoids error scenarios when an LDAP schema doesn't include specific attributes.

ThreatInsight coverage on core Okta API endpoints

Okta ThreatInsight coverage is now available for core Okta API endpoints:

Based on heuristics and machine learning models, Okta ThreatInsight maintains an evolving list of IP addresses that consistently show malicious activity across Okta's customer base. Requests from these bad IP addresses can be blocked or elevated for further analysis when Okta ThreatInsight is enabled for an Okta org. Previously, Okta ThreatInsight coverage only applied to Okta authentication endpoints (including enrollment and recovery endpoints). With this release, enhanced attack patterns are detected for authentication endpoints and limited attack patterns are also detected for non-authentication endpoints. There are no changes to the existing Okta ThreatInsight configuration. You can still enable Okta ThreatInsight with log and block mode, log mode, and exempt network zones. A new Negative IP Reputation reason is available for high security.threat.detected events. See System Log events for Okta ThreatInsight.