Okta Classic Engine release notes (Production)
Generally Available
Version: 2026.08.0
- Import AI agents from Workday
You can now import and manage AI agents built in the Workday Agent System of Record (ASOR) directly through Okta. See AI agent imports.
- Provisioning for Barracuda
Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.
- Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
- Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
- Provisioning for SafetyCulture
Provisioning is now available for the SafteyCulture app integration. See Integrate Safetyculture with Okta.
- Provisioning for Toggl
Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.
- Provisioning for Moodle
Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.
- Provisioning for Elastic Search
Provisioning is now available for the Elastic Search app integration. See Integrate Elastic Search with Okta.
- Provisioning for QualtricsXM
Provisioning is now available for the QualtricsXM app integration. See Integrate Qualtrics XM with Okta.
- Provisioning for HERE
Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.
- Okta Provisioning Agent, version 3.3.0
Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.
- Okta Active Directory agent, version 3.23.0
This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.
- New Research Release lifecycle
A new Research Release lifecycle, marked with a Research Release banner, is now available for Okta admin documentation. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.
- New Proxy service for enhanced dynamic zones
PROXYLINE_PROXY is now supported as an individual Proxy service category in enhanced dynamic zones. See Supported IP categories.
- Request subscriptions data export
To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.
- New System Log events for Office 365 app-based provisioning
The System Log now logs the following events for app-based authentication for Office 365 provisioning:
app.office365.provisioning_app.create: This event is logged when Okta creates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning.app.office365.provisioning_app_credential.rotate: This event is logged when Okta rotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning. TheOutcomefield in this event's data indicates whether the client secret rotation was successful or not.- Application-based authentication for Office 365 provisioning
Okta now creates a dedicated app in your Microsoft Entra ID tenant instead of a service account for User Sync and Universal Sync provisioning. This app supports app-based authentication and helps improve your org's security. If you have existing User Sync or Universal Sync configurations, you must reauthenticate and consent to two new permissions by September 30, 2026. See Provide Microsoft admin consent for Okta.
- Update group rule assignments
Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.
- Import unlicensed users from Azure Active Directory to Okta
You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.
- On-demand rotation of Office 365 SSO signing certificates
Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.
Early Access
- Synchronize device data with Anything-as-a-Source
In addition to users and groups, Custom Identity Source integrations can now synchronize device data from a source of truth. Devices use a fixed set of attributes:
serialNumber,platform, anddisplayName. See Use Anything-as-a-Source.- New System Log events for bulk device changes
The following System Log events are now available for bulk device changes:
system.identity_sources.bulk_device_upsertsystem.identity_sources.bulk_device_delete
- Multiple audiences for custom authorization servers
Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.
Documentation updates
- Okta Engine version switcher on okta-help.pixtulate.com
You can now verify whether a topic on okta-help.pixtulate.com applies to Identity Engine or Classic Engine and switch directly to the equivalent page in one click. The switcher stays visible as you scroll through the page. If a topic is unique to one engine, a
No matching topic for [Identity/Classic] enginemessage appears.
Fixes
-
In Security > Identity Providers, the Reset Certificate Chain button for Smart Card identity providers was available for read-only admins. (OKTA-1205602)
-
The
user.authentication.ssoevent was missing from the System Log when SAML inline hooks threw 5xx errors. (OKTA-1223139) -
Some sign-in attempts that referenced an unresolved bookmark app link returned the wrong type of error message. (OKTA-1234441)
-
When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile. (OKTA-1235909)
Okta Integration Network
-
StackAdapt (OIDC) was updated. Learn More.
-
Clutch Security (API Service) was updated. Learn More.
-
X (Twitter) (SWA) was updated.
-
Mountain Goat is now available. Learn more.
-
Alpacon now supports Express Configuration.
-
Alpacon (OIDC) is now available. Learn more.
-
Finopz (OIDC) is now available. Learn more.
-
Skillcast (SAML) is now available. Learn more.
-
Skillcast (SCIM) is now available. Learn more.