Okta Identity Engine release notes (Production)
Generally Available
Version: 2026.09.0
- Device assurance OS version update
The following OS versions are now supported in device assurance policies: Android 14, 15, 16, 17 (
2026-08-01)- New IP service categories for enhanced dynamic zones
Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
- Cross App Access support for AI agents and apps for all customers
Use XAA to secure access between custom SSO-agentic requesting apps and SSO resource apps. XAA enables customers to connect AI agents and apps to take action on behalf of a user, and removes the need for user consent at runtime. The XAA connection is managed by Okta admins, providing them with visibility and control over which actions an AI agent can take on behalf of a user across the supported OIDC and SAML SSO protocols.
- For the agentic requesting app configuration, see Add AI agents manually, and select your SSO agentic app in User access > App used for access configuration.
- For the XAA resource app configuration, see Configure resource server connectors. If you're configuring an OIN resource app, it must already have XAA enabled.
- To connect the AI agent to the resource app, see Connect AI agents to resources and select Application as the resource type, and then select your resource app.
For agentic requesting apps that use OIDC for SSO, Okta enables binding an AI agent with an OIDC SSO app so that they share the same credentials. If you want to remove this configuration in Okta, delete the AI agent and the corresponding OIDC app.
From this AI agent-app binding capability, admins can now configure direct user authentication for the AI agent. If you have an Okta for AI Agent org and have previously used the Delegation tab to configure AI agent access through delegation links, you need to reconfigure them with the User access tab. See the Migration from Okta for AI Agent delegation link guidance.
- Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- macOS 14.8.9
- macOS 15.7.9
- macOS 26.6.1
- Unified identity for AI agents
Admins can now use an external identifier to ensure their org's registered AI agents are unique. They can also configure creation and matching criteria for imported AI agents, and preview imported AI agents before they're registered. See Enable AI agent imports for an app.
- Okta On-Prem MFA agent version 1.8.7
This version includes security enhancements.
- UI updates for AI agent client registration
On the AI agent > Client registration tab, the authentication methods are now displayed vertically and provide a Configure button. When you click Configure, you're directed to a configuration page for the authentication method.
- Radius Agent version 2.27
This version includes internal improvements and fixes.
- JA4 TLS fingerprinting
Okta now captures JA4 TLS client fingerprints across Syslog event types (
securityContext.tlsFingerprint.ja4 pr), instead of just a curated subset. This includes telephony events (for example, OTP/SMS delivery) along with sign-in, auth, and token events. This provides customers and Okta's security teams with fingerprint-level visibility to spot bot traffic, toll fraud, and other TLS-based attack patterns that IP/user-agent signals miss on their own.This is not yet available for orgs on custom-hosted domains.
- Enhanced import monitoring with real-time updates
You can now view real-time progress for imports from the Import Monitoring dashboard. This provides greater visibility into the current status of in-progress imports such as the number of data chunks currently being processed.
- Copy email from-addresses to the default brand domain
You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.
- Manual MCP registration
Admins can now manually configure authorization server details and client credentials when registering MCP servers. This allows registration of internal or legacy MCP servers that don't support automated metadata discovery endpoints. See Add MCP servers.
- Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- macOS (
26.6.2) - iOS (
26.6.1,18.7.10) - Windows 10 builds (
10.0.17763.9121,10.0.19044.7663,10.0.19045.7663) - Windows 11 builds (
10.0.22631.7517,10.0.26100.9168,10.0.26200.9168)
- macOS (
- Authentication requirement for AI agent app
When an AI agent is bound to an app, the User access tab now displays the authentication requirement for the app. It also provides a link to the app's Sign On tab where you can configure an authentication policy.
- JAMF Pro integration updates
The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM
userNameattribute.- Improved MCP server registration UI
MCP server registration has been updated with improved UI for scope handling and tool visibility.
- Provisioning for WordPress
Provisioning is now available for the WordPress integration. See Integrate WordPress with Okta.
- Provisioning for Ivanti
Provisioning is now available for the Ivanti integration. See Integrate Ivanti with Okta.
- Provisioning for Progress Chef
Provisioning is now available for the Progress Chef integration. See Integrate Progress Chef with Okta.
- SAP Connector
The SAP integration has been migrated to use the SCIM 2.0 API, and the connector's internal HTTP helper has been updated to support this standard.
- Dynamic Client Registration support for MCP server registration
Admins can now select Dynamic Client Registration (DCR) when manually registering an MCP server. When you select this option, Okta automatically registers a client with the provider and populates the credentials. See Manually add MCP servers. This feature is following a slow rollout with preview deployment throughout mid-September, followed by production.
- Okta Integration Network MCP server
You can now add MCP servers from an Okta Integration Network catalog entry, without entering its connection details manually. See Add an MCP server from the OIN catalog. This feature is following a slow rollout with preview deployment throughout mid-September, followed by production.
- DBSSO device probing improvement
DBSSO now relies on the device-registered conditions that are configured in an app's sign-on policy instead of using org-wide probing methods.
- Remote Desktop detection
Admins can now detect and control access from remote desktops using a new
REMOTE_DESKTOPIP service category in Enhanced Dynamic Network Zones. Admins can include or excludeREMOTE_DESKTOPwhen configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these networks. See Supported IP service categories.- Email notifications for disrupted AD and LDAP agents
System email notifications now include options for Active Directory and LDAP agent disruption and recovery. Admins can enable notifications in the Admin Console to receive email alerts when an agent disrupts and recovers.
- Provisioning for Vercel
Provisioning is now available for the Vercel integration. See Integrate Vercel with Okta.
- Increased Access Request limit
The following Access Request limits have been increased:
- Users per task or question: 25 (previously 10)
- Entitlement bundles in an access level condition: 1,000 (previously 100)
- Groups in an access level condition: 1,000 (previously 500)
- Request type configuration lists per org: 250 (previously 100)
- Request types per org: 750 (previously 500)
- Malware Proxy Detection
Admins can now detect and control access from known malware proxy networks using a new
MALWARE_PROXIESIP service category in Enhanced Dynamic Network Zones. This category is powered by Okta's CyberDefense, covering proxy services associated with malware and botnet activity (including 911 S5, NSOCKS, iProxy, BHProxies, and others). Admins can include or excludeMALWARE_PROXIESwhen configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these proxy networks. See Supported IP service categories.- Okta Integration Wizard
Use the Okta Integration Wizard (OIW) to create and deploy custom app integrations in your Okta org. You can configure SSO, SCIM provisioning, Entitlement Management, Universal Logout, API service integration, and custom API Integration Actions capabilities for the app integration. You can use the app integration as a template to create multiple app instances in your org without reconfiguring each app instance. This helps you manage your custom integrations more efficiently and avoid workarounds for SCIM and custom Workflows connectors. See Okta Integration Wizard.
- WebAuthn enrollment failure events in the System Log
The System Log now logs failed WebAuthn (FIDO2) enrollment attempts, using the
user.mfa.factor.activateevent and debug data such as AAGUID,isBackupEligible, and matched authenticator groups. Previously, only successful enrollments were logged. You can use this to identify which authenticator models don't enroll.- Tool discovery for MCP servers
When you register an MCP server, you can now test your credentials and discover its available tools. This ensures your connections are fully verified and lets you view the MCP server's capabilities. See Add MCP servers.
- Okta Provisioning Agent, version 3.3.1
Okta Provisioning Agent 3.3.1 is now available. This release updates the bundled JDK patch version and includes security enhancements. See Okta Provisioning Agent and SDK version history.
- Task count optimization
To improve performance in the Admin Console, the Tasks page now displays an approximate count of
999+when a task contains more than 1,000 items.
Early Access
- Desktop MFA Factor Discovery for Windows
Desktop MFA for Windows now shows users only the MFA factors they've enrolled, instead of a fixed list of all available factors. New users without an enrolled factor can sign in during their grace period to set up MFA, while existing users signing in on a new device must verify with an existing factor. See Enable Desktop MFA Factor Discovery.
- Okta On-prem SCIM Server agent is now Okta On-prem SCIM agent
Okta On-prem SCIM Server agent has been replaced by Okta On-prem SCIM agent. This change reduces the number of dependencies and allows for new features to be implemented. See On-prem Connector for Generic Databases.
- Realm assignment limit increase
The maximum number of realm assignments allowed per profile source has been increased from 30 to 100. This enables admins to scale user organization and management across a larger number of realms. See Realms.
- NFC authenticator
Okta now supports an NFC authenticator as an authentication method for frontline workers signing in to Okta-protected apps on Windows desktop shared workstations. To authenticate, an end user taps their NFC badge on a reader and enters a PIN to meet MFA requirements, without needing a phone, password, or shared account. See NFC authenticator.
- Entitlement import safeguards
Entitlement import safeguards prevent user imports from accidentally removing app roles or licenses when a user is unassigned from an app. Admins can configure safeguards per app using either percentage-based or absolute count thresholds, and optionally block imports that modify or delete entitlement schemas. See Import safeguards.
- Applications page enhancements
The Applications page now provides options to filter apps by type and status, search apps by name or client ID, and view apps by last modified date. You can also export apps to CSV to turn your filtered list into an audit-ready report. During Early Access, labelling uses IGA Governance Labels and is only available for OIG customers. See Search, filter, and export app integrations and Resource labels.
- Low-Code Sign In Customization
Customizations are a key concern for enterprises. Few things have as much impact on customer trust as the look and feel of their site branding. It's how users know to trust the site and learn about new offerings. With Low-Code Sign In Customization, admins can customize the text, colors, and images of their Sign-In Widget without the need for complicated or risky changes using the code editor. A JSON templating language with syntax highlighting and suggestions enable admins to make visual changes to the sign-in page and Interstitial authentication to match their desired experience without changing a line of code. See Customize your sign-in page.
- On-prem Connector for Generic Databases supports high availability using Unified OPS Agent
The On-prem Connector for Generic Databases now supports high availability, which lets you assign multiple Okta On-Premises SCIM Agents to a single app instance so that any available agent can service an import or provisioning operation. This removes the single point of failure for on-premises database integrations and keeps them running while an individual agent is offline or being upgraded. See On-prem Connector for Generic Databases.
- On-prem Connector for Generic Databases supports incremental imports
The On-prem Connector for Generic Databases now supports incremental imports, which retrieves only the users and entitlement assignments that have changed since the last successful import, rather than the full dataset. This reduces import duration and database load for large-scale deployments. The source database must use soft deletes and maintain an automatically updated timestamp column. See On-prem Connector for Generic Databases.
Fixes
-
Push notifications for Okta Verify challenges during direct authentication sometimes failed with a direct_auth_policy_denied error when biometric verification wasn't enrolled. (OKTA-1099950)
-
Password policy errors related to breached credentials protection persisted after admins resolved the issues. (OKTA-1239168)
-
Some links on the Sign-In Help page didn't meet the minimum contrast ratio. (OKTA-1241201)
-
Newly imported Active Directory users couldn't activate their accounts through email links when out-of-band Okta Verify enrollment was enabled in the Okta account management policy. (OKTA-1250588)
-
When no passkeys were enrolled, the End-User Dashboard showed the security method label as Security Key or Biometric Authenticator instead of Passkey. (OKTA-1258336)
-
Some custom profile attributes were still visible in the UI after they were deleted by an admin. (OKTA-1260654)
-
When using Okta as a certificate authority (CA) instead of a third-party CA, the Okta CA didn't permit device re-registration after the device was deleted from Okta. (OKTA-1261907)
-
For AI agents with user sign-on delegations, the deprecation banner on the User access tab displayed incorrect information. (OKTA-1262867)
-
Custom admin roles could generate a Desktop MFA recovery PIN for users who weren't in their resource group if they had the device level recovery PIN permission. (OKTA-1264620)
-
When the Flexible Okta Verify authenticator configuration was enabled, end users who signed in to RADIUS apps with Okta Verify - Push received an error. (OKTA-1265932)
Okta Integration Network
-
Harriet (SCIM) was updated. Learn more.
-
Your360 (OIDC) is now available. Learn more.
-
Your360 (SAML) is now available. Learn more.
-
Harriet (OIDC) was updated.
-
Sensor Tower (SCIM) is now available. Learn more.
-
Visily Lifecycle Management Connector By Redblock (SCIM) is now available. Learn more.
-
Instagram (SWA) was updated.