Okta Identity Engine release notes (Production)

Generally Available

Version: 2026.08.0

Import AI agents from Microsoft Office 365

You can now import and manage AI agents built in Microsoft Copilot Studio and Microsoft AI Foundry directly through Okta. See AI agent imports.

Import AI agents from Workday

You can now import and manage AI agents built in the Workday Agent System of Record (ASOR) directly through Okta. See AI agent imports.

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • Android 13, 14, 15, 16 security patch 2026-01-05
Anthropic (Claude) SAML SSO integration

A new SAML 2.0 SSO integration for Anthropic (Claude) is now available on the Okta Integration Network, with the existing Anthropic AI Agent integration bundled in.

Claude supports SAML 2.0 SSO

The Claude app integration now supports SAML 2.0 SSO. Orgs that are subscribed to Okta for AI Agents can continue using the integration to import Claude Managed Agents into Okta. See Integrate Claude with Okta.

Provisioning for Barracuda

Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.

Provisioning for Linear

Linear provisioning is now available. See Create Linear integration.

Provisioning for Appspace

Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.

Sign-In Widget, version 7.47.1

For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.

Agent-to-agent audience update

The agent-to-agent server resource url (audience parameter) can now be a free-form string.

Cross app access for AI agents and apps

Cross app access now secures connections between custom SAML requesting apps and OIDC/SAML resource apps. This feature allows admins to securely connect AI agents and apps to take action on behalf of users, bypassing the need for user consent. Admins retain full visibility and granular control over every action an AI agent can execute for a user. See Configure resource server connectors.

Provisioning for SafetyCulture

Provisioning is now available for the SafteyCulture app integration. See Integrate Safetyculture with Okta.

Provisioning for Toggl

Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.

Provisioning for Moodle

Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.

Agent-to-agent connections

Agent-to-agent server connections allow admins to connect AI agents to other AI agents. Admins can manage scopes to restrict access to the appropriate AI agent tasks, and allow service apps to call AI agents without user context. Using tokens and the System Log, admins can view all the users, AI agents, and apps that call an AI agent. See Agent-to-agent connections.

Provisioning for Elastic Search

Provisioning is now available for the Elastic Search app integration. See Integrate Elastic Search with Okta.

Provisioning for QualtricsXM

Provisioning is now available for the QualtricsXM app integration. See Integrate Qualtrics XM with Okta.

Provisioning for HERE

Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.

Editable issuer URL for AI agent resource connections

Now when you create a resource connection between an AI agent and an authorization server, you can modify the authorization server's issuer URL.

Skipped failed entries during AI agent import

Now when you import AI agents from a provider, Okta skips the failed entries and creates or updates the successful ones. 

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • Android 14, 15, 16, 17 (2026-07-01)
  • Windows 10 builds (10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548)
  • Windows 11 builds (10.0.22631.7376, 10.0.26100.8875, 10.0.26200.8875)
Import AI agents from Langsmith

You can now import and manage AI agents built in the Langsmith Deployments directly through Okta. See AI agent imports.

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • macOS (26.6, 15.7.8, 14.8.8)
  • iOS (26.6)
Sign-In Widget, versions 7.48.1 and 7.48.0

For details about these releases, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.

Improved smart card enrollment

Users can now enroll a smart card even if the login attribute doesn't match the value mapped from the card. Previously, enrollment failed during dynamic matching or Just-In-Time provisioning because the login attribute was treated as restricted from updates. See Add a Smart Card identity provider.

Okta Provisioning Agent, version 3.3.0

Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.

Okta Active Directory agent, version 3.23.0

This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.

New Research Release lifecycle

A new Research Release lifecycle, marked with a Research Release banner, is now available for Okta admin documentation. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.

Improved system log events for IdP routing

System log events for IdP routing now include the target information from the IdP Discovery rule that matched, when available.

New minimum character length for AI agent names

AI agent names now must contain a minimum of three characters. 

New Proxy service for enhanced dynamic zones

PROXYLINE_PROXY is now supported as an individual Proxy service category in enhanced dynamic zones. See Supported IP categories.

Request subscriptions data export

To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.

New target for user.risk.detect events

Identity Threat Protection now populates affected factors in the user.risk.detect event's target for entity critical actions for high-threat IPs.

New System Log events for Office 365 app-based provisioning

The System Log now logs the following events for app-based authentication for Office 365 provisioning: app.office365.provisioning_app.create: This event is logged when Okta creates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning. app.office365.provisioning_app_credential.rotate: This event is logged when Okta rotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning. The Outcome field in this event's data indicates whether the client secret rotation was successful or not.

Advanced posture checks for device assurance

Advanced posture checks let admins configure specific device security conditions beyond what standard device assurance policies support. Using osquery, you can write custom SQL queries to assess device state on macOS and Windows devices, configure checks for unmanaged devices, and integrate with endpoint detection and response (EDR) tools. See Configure advanced posture checks for device assurance.

Strong cipher enforcement for X.509 client certificate authentication

Okta now enforces strong cryptographic ciphers for X.509 client certificates used in mTLS authentication. Client certificates signed with weak ciphers, such as RSA-1024, are no longer accepted for new orgs. If you use X.509 certificate-based authentication, ensure that your client certificates meet FIPS 140-2 cipher requirements.

Updated passkey enrollment screen

The passkey enrollment screen in the Sign-In Widget now includes updated copy and an informational image to help users understand what a passkey is before they enroll.

Customizable emails for Passkeys (FIDO2 WebAuthn) authenticator

The email that users receive when the admin configures a Passkeys (FIDO2 WebAuthn) authenticator is now available as a customizable template in Customizations > Brands > Emails. Admins can modify the subject line, email body, and dynamic variables such as the PIN, first name, and org name, and can add content in multiple languages. 

Email auto-enrollment and recovery management

Admins can control the automatic enrollment of email as an authenticator and configure email-based password recovery, unlock, and change where email isn't an authenticator. See Make email an optional authenticator.

Application-based authentication for Office 365 provisioning

Okta now creates a dedicated app in your Microsoft Entra ID tenant instead of a service account for User Sync and Universal Sync provisioning. This app supports app-based authentication and helps improve your org's security. If you have existing User Sync or Universal Sync configurations, you must reauthenticate and consent to two new permissions by September 30, 2026. See Provide Microsoft admin consent for Okta.

MCP Servers and Resource Servers moved to Applications and Resources

In the Admin Console, the MCP Servers and Resource Servers pages have moved from the Directory menu to the Applications and Resources menu.

Applications menu renamed to Applications and Resources

In the Admin Console, the Applications menu is now called Applications and Resources.

Enhanced Breached Credentials Protection

This feature provides a premium breached credentials detection feed for Okta Customer Identity (OCI) customers with Identity Threat Protection which identifies more compromised credentials sooner. See Breached credentials protection.

Update group rule assignments

Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.

Import unlicensed users from Azure Active Directory to Okta

You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.

Identity verification with vendor-submitted integrations

Identity verification (IDV) vendors can now submit integrations through the Okta Integration Network. You can configure and apply these integrations to your authentication policies to verify user identities.

On-demand rotation of Office 365 SSO signing certificates

Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.

Early Access

Synchronize device data with Anything-as-a-Source

In addition to users and groups, Custom Identity Source integrations can now synchronize device data from a source of truth. Devices use a fixed set of attributes: serialNumber, platform, and displayName. See Use Anything-as-a-Source.

Policy change management

Admins can create branches of their app sign-in policies to review and monitor the impact of changes before enforcing the policy for end users. This allows admins to draft policy changes, test them against real user traffic, and roll them out with confidence. See Manage app sign-in policy branches.

Identity verification with vendor-submitted integrations

Identity verification (IDV) vendors can now submit integrations through the Okta Integration Network. You can configure and apply these integrations to your authentication policies to verify user identities.

Import AI agents from Glean

You can now import and manage AI agents built in the Glean Agent Builder directly through Okta. See AI agent imports.

Okta Verify Device Posture Sensor Mode

Previously, enforcing device security posture created significant blind spots on shared devices because it required a single-user Okta FastPass enrollment. Okta Verify Sensor Mode resolves this issue by registering the app directly to the org, allowing context-aware Device Assurance policies to be instantly evaluated when the user signs in. This is especially valuable for frontline workers, as it guarantees comprehensive compliance for shared fleets and ensures that devices are healthy before access is ever granted. See Device Posture Sensor Mode.

Device Visibility feature for macOS and Windows

Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.

Removal of Cross App Access configuration using Managed Connection

The removal of the ability to configure cross app access from the Managed connection tab located on the app's profile page is scheduled for an upcoming release. When it's removed, your existing configurations will stop working. Reconfigure your connections from the Resource Server tab to avoid disruptions. See Connect AI agents to resources.

New System Log events for bulk device changes

The following System Log events are now available for bulk device changes:

  • system.identity_sources.bulk_device_upsert
  • system.identity_sources.bulk_device_delete
Device Visibility feature for macOS and Windows

Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.

Multiple audiences for custom authorization servers

Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.

Flexible Okta Verify authenticator configuration

Okta Verify is bundled into a single authenticator with org-wide settings, preventing you from configuring individual verification methods (Okta FastPass, Push notification, or TOTP) per group. This feature separates Okta Verify into distinct, method-specific authenticators, allowing you to roll out Okta FastPass gradually.

Passkey enrollment promotion prompt

You can now configure a passkey enrollment promotion nudge that prompts end users to enroll a passkey authenticator when they sign in. The nudge applies only when the passkey authenticator is optional, and users who skip it can still sign in with another authenticator. You can control how often the prompt reappears and how many times a user can skip it before Okta stops showing it. See Create an authenticator enrollment policy.

User identification policy

Admins can now manage rules in the user identification policy to control whether the Sign in with Okta FastPass button appears on an app-by-app basis, instead of relying on a single org-wide setting. This makes it easier to manage pilot groups during Okta FastPass rollouts and to tailor the sign-in experience for individual apps. See Add a rule to a user identification policy.

Documentation updates

Okta Engine version switcher on help.okta.com

You can now verify whether a topic on help.okta.com applies to Identity Engine or Classic Engine and switch directly to the equivalent page in one click. The switcher stays visible as you scroll through the page. If a topic is unique to one engine, a No matching topic for [Identity/Classic] engine message appears.

Fixes

  • In Security > Identity Providers, the Reset Certificate Chain button for Smart Card identity providers was available for read-only admins. (OKTA-1205602)

  • The user.authentication.sso event was missing from the System Log when SAML inline hooks threw 5xx errors. (OKTA-1223139)

  • The OAuth secure token exchange (STS) fields were visible for resource server apps that don't support the STS protocol.  (OKTA-1226327)

  • Some sign-in attempts that referenced an unresolved bookmark app link returned the wrong type of error message. (OKTA-1234441)

  • When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile.  (OKTA-1235909)

Okta Integration Network

  • StackAdapt (OIDC) was updated. Learn More.

  • Clutch Security (API Service) was updated. Learn More.

  • X (Twitter) (SWA) was updated.

  • Mountain Goat is now available. Learn more.

  • Alpacon now supports Express Configuration.

  • Alpacon (OIDC) is now available. Learn more.

  • Finopz (OIDC) is now available. Learn more.

  • Skillcast (SAML) is now available. Learn more.

  • Skillcast (SCIM) is now available. Learn more.