Okta Classic Engine release notes (Production)

Generally Available

Version: 2026.08.0

Import AI agents from Workday

You can now import and manage AI agents built in the Workday Agent System of Record (ASOR) directly through Okta. See AI agent imports.

Provisioning for Barracuda

Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.

Provisioning for Linear

Linear provisioning is now available. See Create Linear integration.

Provisioning for Appspace

Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.

Provisioning for SafetyCulture

Provisioning is now available for the SafteyCulture app integration. See Integrate Safetyculture with Okta.

Provisioning for Toggl

Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.

Provisioning for Moodle

Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.

Provisioning for Elastic Search

Provisioning is now available for the Elastic Search app integration. See Integrate Elastic Search with Okta.

Provisioning for QualtricsXM

Provisioning is now available for the QualtricsXM app integration. See Integrate Qualtrics XM with Okta.

Provisioning for HERE

Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.

Okta Provisioning Agent, version 3.3.0

Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.

Okta Active Directory agent, version 3.23.0

This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.

New Research Release lifecycle

A new Research Release lifecycle, marked with a Research Release banner, is now available for Okta admin documentation. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.

New Proxy service for enhanced dynamic zones

PROXYLINE_PROXY is now supported as an individual Proxy service category in enhanced dynamic zones. See Supported IP categories.

Request subscriptions data export

To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.

New System Log events for Office 365 app-based provisioning

The System Log now logs the following events for app-based authentication for Office 365 provisioning: app.office365.provisioning_app.create: This event is logged when Okta creates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning. app.office365.provisioning_app_credential.rotate: This event is logged when Okta rotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning. The Outcome field in this event's data indicates whether the client secret rotation was successful or not.

Application-based authentication for Office 365 provisioning

Okta now creates a dedicated app in your Microsoft Entra ID tenant instead of a service account for User Sync and Universal Sync provisioning. This app supports app-based authentication and helps improve your org's security. If you have existing User Sync or Universal Sync configurations, you must reauthenticate and consent to two new permissions by September 30, 2026. See Provide Microsoft admin consent for Okta.

Update group rule assignments

Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.

Import unlicensed users from Azure Active Directory to Okta

You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.

On-demand rotation of Office 365 SSO signing certificates

Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.

Early Access

Synchronize device data with Anything-as-a-Source

In addition to users and groups, Custom Identity Source integrations can now synchronize device data from a source of truth. Devices use a fixed set of attributes: serialNumber, platform, and displayName. See Use Anything-as-a-Source.

New System Log events for bulk device changes

The following System Log events are now available for bulk device changes:

  • system.identity_sources.bulk_device_upsert
  • system.identity_sources.bulk_device_delete
Multiple audiences for custom authorization servers

Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.

Documentation updates

Okta Engine version switcher on okta-help.pixtulate.com

You can now verify whether a topic on okta-help.pixtulate.com applies to Identity Engine or Classic Engine and switch directly to the equivalent page in one click. The switcher stays visible as you scroll through the page. If a topic is unique to one engine, a No matching topic for [Identity/Classic] engine message appears.

Fixes

  • In Security > Identity Providers, the Reset Certificate Chain button for Smart Card identity providers was available for read-only admins. (OKTA-1205602)

  • The user.authentication.sso event was missing from the System Log when SAML inline hooks threw 5xx errors. (OKTA-1223139)

  • Some sign-in attempts that referenced an unresolved bookmark app link returned the wrong type of error message. (OKTA-1234441)

  • When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile.  (OKTA-1235909)

Okta Integration Network

  • StackAdapt (OIDC) was updated. Learn More.

  • Clutch Security (API Service) was updated. Learn More.

  • X (Twitter) (SWA) was updated.

  • Mountain Goat is now available. Learn more.

  • Alpacon now supports Express Configuration.

  • Alpacon (OIDC) is now available. Learn more.

  • Finopz (OIDC) is now available. Learn more.

  • Skillcast (SAML) is now available. Learn more.

  • Skillcast (SCIM) is now available. Learn more.