Okta Identity Engine release notes (Preview)

Generally Available

Version: 2026.08.0

Import AI agents from Workday

You can now import and manage AI agents built in the Workday Agent System of Record (ASOR) directly through Okta. See AI agent imports.

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • Android 13, 14, 15, 16 security patch 2026-01-05
Claude supports SAML 2.0 SSO

The Claude app integration now supports SAML 2.0 SSO. Orgs that are subscribed to Okta for AI Agents can continue using the integration to import Claude Managed Agents into Okta. See Integrate Claude with Okta.

Provisioning for Barracuda

Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.

Provisioning for Linear

Linear provisioning is now available. See Create Linear integration.

Provisioning for Appspace

Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.

Agent-to-agent audience update

The agent-to-agent server resource url (audience parameter) can now be a free-form string.

Provisioning for Toggl

Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.

Provisioning for Moodle

Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.

Provisioning for HERE

Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.

Editable issuer URL for AI agent resource connections

Now when you create a resource connection between an AI agent and an authorization server, you can modify the authorization server's issuer URL.

Skipped failed entries during AI agent import

Now when you import AI agents from a provider, Okta skips the failed entries and creates or updates the successful ones. 

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • Android 14, 15, 16, 17 (2026-07-01)
  • Windows 10 builds (10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548)
  • Windows 11 builds (10.0.22631.7376, 10.0.26100.8875, 10.0.26200.8875)
Import AI agents from Langsmith

You can now import and manage AI agents built in the Langsmith Deployments directly through Okta. See AI agent imports.

Device assurance OS version update

The following OS versions are now supported in device assurance policies:

  • macOS (26.6, 15.7.8, 14.8.8)
  • iOS (26.6)
Improved smart card enrollment

Users can now enroll a smart card even if the login attribute doesn't match the value mapped from the card. Previously, enrollment failed during dynamic matching or Just-In-Time provisioning because the login attribute was treated as restricted from updates. See Add a Smart Card identity provider.

Okta Provisioning Agent, version 3.3.0

Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.

Okta Active Directory agent, version 3.23.0

This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.

New Research Release lifecycle

A new Research Release lifecycle is now available, marked with a Research Release banner in Okta admin documentation and visible in the Admin Console under Settings > Features. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.

Improved system log events for IdP routing

System log events for IdP routing now include the target information from the IdP Discovery rule that matched, when available.

New minimum character length for AI agent names

AI agent names now must contain a minimum of three characters. 

Request subscriptions data export

To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.

New target for user.risk.detect events

Identity Threat Protection now populates affected factors in the user.risk.detect event's target for entity critical actions for high-threat IPs.

Malware Proxy Detection

Admins can now detect and control access from known malware proxy networks using a new MALWARE_PROXIES IP service category in Enhanced Dynamic Network Zones. This category is powered by Okta's CyberDefense, covering proxy services associated with malware and botnet activity (including 911 S5, NSOCKS, iProxy, BHProxies, and others). Admins can include or exclude MALWARE_PROXIES when configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these proxy networks. See Supported IP service categories.

SAP SuccessFactors OAuth 2.0 with SAML Assertion

The SAP SuccessFactors app integration now supports OAuth 2.0 with SAML Assertion for enhanced API security. To ensure your provisioning and sync processes continue without interruption, you must migrate to this new authentication method before the SAP Basic Authentication deletion deadline on November 20, 2026. See Configure OAuth 2.0 with SAML for SAP SuccessFactors.

Okta Integration Wizard

Use the Okta Integration Wizard (OIW) to create and deploy custom app integrations in your Okta org. You can configure SSO, SCIM provisioning, Entitlement Management, Universal Logout, and custom API Integration Actions capabilities for the app integration. You can use the app integration as a template to create multiple app instances in your org without reconfiguring each app instance. This helps you manage your custom integrations more efficiently and avoid workarounds for SCIM and custom Workflows connectors. See Okta Integration Wizard.

Updated passkey enrollment screen

The passkey enrollment screen in the Sign-In Widget now includes updated copy and an informational image to help users understand what a passkey is before they enroll.

WebAuthn enrollment failure events in the System Log

The System Log now logs failed WebAuthn (FIDO2) enrollment attempts, using the user.mfa.factor.activate event and debug data such as AAGUID, isBackupEligible, and matched authenticator groups. Previously, only successful enrollments were logged. You can use this to identify which authenticator models don't enroll.

MCP Servers and Resource Servers moved to Applications and Resources

In the Admin Console, the MCP Servers and Resource Servers pages have moved from the Directory menu to the Applications and Resources menu.

Applications menu renamed to Applications and Resources

In the Admin Console, the Applications menu is now called Applications and Resources.

Direct End-User Settings access

Users may now access their Settings page through a direct URL in addition to the End-User Dashboard. This feature provides convenience and security for users, gives admins greater flexibility when working with End-User Dashboard access control scenarios, and includes accessibility and UX improvements. See End-User Settings.

Early Access

Synchronize device data with Anything-as-a-Source

In addition to users and groups, Custom Identity Source integrations can now synchronize device data from a source of truth. Devices use a fixed set of attributes: serialNumber, platform, and displayName. See Use Anything-as-a-Source.

Policy change management

Admins can create branches of their app sign-in policies to review and monitor the impact of changes before enforcing the policy for end users. This allows admins to draft policy changes, test them against real user traffic, and roll them out with confidence. See Manage app sign-in policy branches.

Identity verification with vendor-submitted integrations

Identity verification (IDV) vendors can now submit integrations through the Okta Integration Network. You can configure and apply these integrations to your authentication policies to verify user identities.

Import AI agents from Glean

You can now import and manage AI agents built in the Glean Agent Builder directly through Okta. See AI agent imports.

Okta Verify Device Posture Sensor Mode

Previously, enforcing device security posture created significant blind spots on shared devices because it required a single-user Okta FastPass enrollment. Okta Verify Sensor Mode resolves this issue by registering the app directly to the org, allowing context-aware Device Assurance policies to be instantly evaluated when the user signs in. This is especially valuable for frontline workers, as it guarantees comprehensive compliance for shared fleets and ensures that devices are healthy before access is ever granted. See Device Posture Sensor Mode.

Device Visibility feature for macOS and Windows

Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.

Removal of Cross App Access configuration using Managed Connection

The removal of the ability to configure cross app access from the Managed connection tab located on the app's profile page is scheduled for an upcoming release. When it's removed, your existing configurations will stop working. Reconfigure your connections from the Resource Server tab to avoid disruptions. See Connect AI agents to resources.

New System Log events for bulk device changes

The following System Log events are now available for bulk device changes:

  • system.identity_sources.bulk_device_upsert
  • system.identity_sources.bulk_device_delete
Device Visibility feature for macOS and Windows

Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.

Multiple audiences for custom authorization servers

Custom authorization servers now support multiple audiences in addition to a default audience. See Create an authorization server.

Flexible Okta Verify authenticator configuration

Okta Verify is bundled into a single authenticator with org-wide settings, preventing you from configuring individual verification methods (Okta FastPass, Push notification, or TOTP) per group. This feature separates Okta Verify into distinct, method-specific authenticators, allowing you to roll out Okta FastPass gradually.

Passkey enrollment promotion prompt

You can now configure a passkey enrollment promotion nudge that prompts end users to enroll a passkey authenticator when they sign in. The nudge applies only when the passkey authenticator is optional, and users who skip it can still sign in with another authenticator. You can control how often the prompt reappears and how many times a user can skip it before Okta stops showing it. See Create an authenticator enrollment policy.

User identification policy

Admins can now manage rules in the user identification policy to control whether the Sign in with Okta FastPass button appears on an app-by-app basis, instead of relying on a single org-wide setting. This makes it easier to manage pilot groups during Okta FastPass rollouts and to tailor the sign-in experience for individual apps. See Add a rule to a user identification policy.

Documentation updates

Okta Engine version switcher on okta-help.pixtulate.com

You can now verify whether a topic on okta-help.pixtulate.com applies to Identity Engine or Classic Engine and switch directly to the equivalent page in one click. The switcher stays visible as you scroll through the page. If a topic is unique to one engine, a No matching topic for [Identity/Classic] engine message appears.

Fixes

  • In Security > Identity Providers, the Reset Certificate Chain button for Smart Card identity providers was available for read-only admins. (OKTA-1205602)

  • The user.authentication.sso event was missing from the System Log when SAML inline hooks threw 5xx errors. (OKTA-1223139)

  • The OAuth secure token exchange (STS) fields were visible for resource server apps that don't support the STS protocol.  (OKTA-1226327)

  • Some sign-in attempts that referenced an unresolved bookmark app link returned the wrong type of error message. (OKTA-1234441)

  • When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile.  (OKTA-1235909)

Okta Integration Network

  • StackAdapt (OIDC) was updated. Learn More.

  • Clutch Security (API Service) was updated. Learn More.

  • X (Twitter) (SWA) was updated.

  • Mountain Goat is now available. Learn more.

  • Alpacon now supports Express Configuration.

  • Alpacon (OIDC) is now available. Learn more.

  • Finopz (OIDC) is now available. Learn more.

  • Skillcast (SAML) is now available. Learn more.

  • Skillcast (SCIM) is now available. Learn more.

2026.08.1: Update 1 started deployment on August 13

Device assurance OS version update
The following OS versions are now supported in device assurance policies:
  • Android 14, 15, 16, 17 (2026-08-01)
New IP service categories for enhanced dynamic zones

Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

Fixes

  • In some orgs, the System Log didn't display user.session.start events consistently for all sign-in attempts. (OKTA-1138083)

  • App-scoped identity provider (IdP) routing rules could route authentication requests to the wrong IdP, causing sign-in failures for users who should have been redirected to a different IdP or the default sign-in page. (OKTA-1176869)

  • When an admin's password was reset, the Admin roles tab disappeared from the user profile page in the Admin Console. (OKTA-1184998)

  • If your custom role included only the Reset users' authenticators permission, you could also incorrectly enroll authenticators on behalf of users. (OKTA-1220095)

  • When an OAuth token grant failed, the resulting System Log event didn't display user details. (OKTA-1229159)

  • When an admin imported Active Directory users, user confirmation failed if a deleted user's attributes conflicted with an incoming user profile. (OKTA-1235909)

  • The OAuth secure token exchange (STS) fields were visible for resource server apps that don't support the STS protocol.  (OKTA-1238571)

  • On the AI agents page, the User sign-on application filter was visible to orgs that weren't subscribed to Okta for AI Agents. (OKTA-1239631)

  • On the Register AI agent page, the helper text below the Name field showed an incorrect minimum character length. (OKTA-1241243)

  • In some orgs, the minimum character length for an AI agent name was five instead of three. (OKTA-1242199)

  • When an admin activated a public/private key for an AI agent, it showed the Disabled status. (OKTA-1245200)

  • When the user interaction requirement for an Okta Account Management Policy rule was set to Any interaction, Okta incorrectly enforced it as if Require device passcode or biometric user verification was selected, which could block users from signing in. (OKTA-1245305)

  • When an admin imported AI agents from Microsoft Copilot Studio or Microsoft Foundry, the configured owners weren't assigned to them. (OKTA-1245342)

Okta Integration Network

  • Airwallex (OIDC) is now available. Learn more.

  • Bold Group Stages (SAML) is now available. Learn more.

  • Gateco (SCIM) is now available. Learn more.

  • NewCore (API Service) was updated.

  • Orca Security (SAML) is now available. Learn more.

  • Orca Security (SCIM) is now available. Learn more.

  • Square (OIDC) is now available. Learn more.

  • Statsig Lifecycle Management Connector by Redblock (SCIM) is now available. Learn more.

  • Vimeo Lifecycle Management Connector by Redblock (SCIM) is now available. Learn more.

Preview org features

Workday supports incremental imports

Workday now has the ability to run immediate, incremental imports. Incremental imports are much faster than full imports. However, they don't detect when users only have changes to custom attributes, so you must periodically run a full import to capture these changes. See Incremental imports.

Same-device enrollment for Okta FastPass

On orgs with Okta FastPass, the Okta Verify enrollment process has been streamlined:

  • Users can initiate and complete enrollment on the device they're currently using. Previously, two different devices were required to set up an account.
  • Users no longer need to enter their org URL during enrollment.
  • The enrollment flow has fewer steps. This feature is supported on Android, iOS, and macOS devices.
End-user setting for nicknaming factors

End users can now nickname their phone, WebAuthn, and Okta Verify factors. If they have enrolled multiple instances of a factor, giving nicknames helps them identify the factors quickly (for example, "My personal cellphone" or "My office MacBook TouchID"). See the end-user documentation. This is a self-service feature.

Descriptive System Log events

When Okta identifies a security threat, the resulting security.threat.detected System Log entry now provides a descriptive reason for the event. See System Log.

New flexible LDAP

A new LDAP schema allows flexibility by moving email to the custom schema and making first name, last name, username, and UID optional. This avoids error scenarios when an LDAP schema doesn't include specific attributes.

ThreatInsight coverage on core Okta API endpoints

Okta ThreatInsight coverage is now available for core Okta API endpoints:

Based on heuristics and machine learning models, Okta ThreatInsight maintains an evolving list of IP addresses that consistently show malicious activity across Okta's customer base. Requests from these bad IP addresses can be blocked or elevated for further analysis when Okta ThreatInsight is enabled for an Okta org. Previously, Okta ThreatInsight coverage only applied to Okta authentication endpoints (including enrollment and recovery endpoints). With this release, enhanced attack patterns are detected for authentication endpoints and limited attack patterns are also detected for non-authentication endpoints. There are no changes to the existing Okta ThreatInsight configuration. You can still enable Okta ThreatInsight with log and block mode, log mode, and exempt network zones. A new Negative IP Reputation reason is available for high security.threat.detected events. See System Log events for Okta ThreatInsight.