Okta Identity Engine release notes (Production)
Generally Available
Version: 2026.08.0
- Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
- Claude supports SAML 2.0 SSO
The Claude app integration now supports SAML 2.0 SSO. Orgs that are subscribed to Okta for AI Agents can continue using the integration to import Claude Managed Agents into Okta. See Integrate Claude with Okta.
- Provisioning for Barracuda
Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.
- Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
- Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
- Agent-to-agent audience update
The agent-to-agent server resource url (
audienceparameter) can now be a free-form string.- Cross app access for AI agents and apps
Cross app access now secures connections between custom SAML requesting apps and OIDC/SAML resource apps. This feature allows admins to securely connect AI agents and apps to take action on behalf of users, bypassing the need for user consent. Admins retain full visibility and granular control over every action an AI agent can execute for a user. See Configure resource server connectors.
- Provisioning for SafetyCulture
Provisioning is now available for the SafteyCulture app integration. See Integrate Safetyculture with Okta.
- Provisioning for Toggl
Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.
- Provisioning for Moodle
Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.
- Provisioning for Elastic Search
Provisioning is now available for the Elastic Search app integration. See Integrate Elastic Search with Okta.
- Provisioning for QualtricsXM
Provisioning is now available for the QualtricsXM app integration. See Integrate Qualtrics XM with Okta.
- Provisioning for HERE
Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.
- Editable issuer URL for AI agent resource connections
Now when you create a resource connection between an AI agent and an authorization server, you can modify the authorization server's issuer URL.
- Skipped failed entries during AI agent import
Now when you import AI agents from a provider, Okta skips the failed entries and creates or updates the successful ones.
- Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 14, 15, 16, 17 (
2026-07-01) - Windows 10 builds (
10.0.17763.9020,10.0.19044.7548,10.0.19045.7548) - Windows 11 builds (
10.0.22631.7376,10.0.26100.8875,10.0.26200.8875)
- Android 14, 15, 16, 17 (
- Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- macOS (26.6, 15.7.8, 14.8.8)
- iOS (26.6)
- Improved smart card enrollment
Users can now enroll a smart card even if the login attribute doesn't match the value mapped from the card. Previously, enrollment failed during dynamic matching or Just-In-Time provisioning because the login attribute was treated as restricted from updates. See Add a Smart Card identity provider.
- Okta Provisioning Agent, version 3.3.0
Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.
- Okta Active Directory agent, version 3.23.0
This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.
- Improved system log events for IdP routing
System log events for IdP routing now include the target information from the IdP Discovery rule that matched, when available.
- New minimum character length for AI agent names
AI agent names now must contain a minimum of three characters.
- Request subscriptions data export
To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.
- Updated passkey enrollment screen
The passkey enrollment screen in the Sign-In Widget now includes updated copy and an informational image to help users understand what a passkey is before they enroll.
- MCP Servers and Resource Servers moved to Applications and Resources
In the Admin Console, the MCP Servers and Resource Servers pages have moved from the Directory menu to the Applications and Resources menu.
- Applications menu renamed to Applications and Resources
In the Admin Console, the Applications menu is now called Applications and Resources.
Early Access
- Synchronize device data with Anything-as-a-Source
In addition to users and groups, Custom Identity Source integrations can now synchronize device data from a source of truth. Devices use a fixed set of attributes:
serialNumber,platform, anddisplayName. See Use Anything-as-a-Source.- Policy change management
Admins can create branches of their app sign-in policies to review and monitor the impact of changes before enforcing the policy for end users. This allows admins to draft policy changes, test them against real user traffic, and roll them out with confidence. See Manage app sign-in policy branches.
- Identity verification with vendor-submitted integrations
Identity verification (IDV) vendors can now submit integrations through the Okta Integration Network. You can configure and apply these integrations to your authentication policies to verify user identities.
- Import AI agents from Glean
You can now import and manage AI agents built in the Glean Agent Builder directly through Okta. See AI agent imports.
- Okta Verify Device Posture Sensor Mode
Previously, enforcing device security posture created significant blind spots on shared devices because it required a single-user Okta FastPass enrollment. Okta Verify Sensor Mode resolves this issue by registering the app directly to the org, allowing context-aware Device Assurance policies to be instantly evaluated when the user signs in. This is especially valuable for frontline workers, as it guarantees comprehensive compliance for shared fleets and ensures that devices are healthy before access is ever granted. See Device Posture Sensor Mode.
- Device Visibility feature for macOS and Windows
Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.
- Removal of Cross App Access configuration using Managed Connection
The removal of the ability to configure cross app access from the Managed connection tab located on the app's profile page is scheduled for an upcoming release. When it's removed, your existing configurations will stop working. Reconfigure your connections from the Resource Server tab to avoid disruptions. See Connect AI agents to resources.
- New System Log events for bulk device changes
The following System Log events are now available for bulk device changes:
system.identity_sources.bulk_device_upsertsystem.identity_sources.bulk_device_delete
- Device Visibility feature for macOS and Windows
Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.
- Multiple audiences for custom authorization servers
Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.
- Flexible Okta Verify authenticator configuration
Okta Verify is bundled into a single authenticator with org-wide settings, preventing you from configuring individual verification methods (Okta FastPass, Push notification, or TOTP) per group. This feature separates Okta Verify into distinct, method-specific authenticators, allowing you to roll out Okta FastPass gradually.
- Passkey enrollment promotion prompt
You can now configure a passkey enrollment promotion nudge that prompts end users to enroll a passkey authenticator when they sign in. The nudge applies only when the passkey authenticator is optional, and users who skip it can still sign in with another authenticator. You can control how often the prompt reappears and how many times a user can skip it before Okta stops showing it. See Create an authenticator enrollment policy.
- User identification policy
Admins can now create a user identification policy to control whether the Sign in with Okta FastPass button appears on an app-by-app basis, instead of relying on a single org-wide setting. This makes it easier to manage pilot groups during Okta FastPass rollouts and to tailor the sign-in experience for individual apps. See User identification policy.
Documentation updates
- Okta Engine version switcher on help.okta.com
You can now verify whether a topic on help.okta.com applies to Identity Engine or Classic Engine and switch directly to the equivalent page in one click. The switcher stays visible as you scroll through the page. If a topic is unique to one engine, a
No matching topic for [Identity/Classic] enginemessage appears.
Fixes
-
In Security > Identity Providers, the Reset Certificate Chain button for Smart Card identity providers was available for read-only admins. (OKTA-1205602)
-
The
user.authentication.ssoevent was missing from the System Log when SAML inline hooks threw 5xx errors. (OKTA-1223139) -
The OAuth secure token exchange (STS) fields were visible for resource server apps that don't support the STS protocol. (OKTA-1226327)
-
Some sign-in attempts that referenced an unresolved bookmark app link returned the wrong type of error message. (OKTA-1234441)
-
When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile. (OKTA-1235909)
Okta Integration Network
-
StackAdapt (OIDC) was updated. Learn More.
-
Clutch Security (API Service) was updated. Learn More.
-
X (Twitter) (SWA) was updated.
-
Mountain Goat is now available. Learn more.
-
Alpacon now supports Express Configuration.
-
Alpacon (OIDC) is now available. Learn more.
-
Finopz (OIDC) is now available. Learn more.
-
Skillcast (SAML) is now available. Learn more.
-
Skillcast (SCIM) is now available. Learn more.