Okta Release Notes

Follow

84 release notes curated from 6 sources by the Releasebot Team. Last updated: Jul 22, 2026

Get this feed:

Okta Products

  • Jul 21, 2026
    • Date parsed from source:
      Jul 21, 2026
    • First seen by Releasebot:
      Jul 22, 2026
    Okta logo

    Okta Identity Engine by Okta

    2026.07.2

    Okta Identity Engine ships Sign-In Widget 7.47.1 with an agent-to-agent audience update that allows a free-form server resource URL, plus a new Device Visibility experience for macOS and Windows that puts key user, enrollment, and security signals in one four-tab view.

    Sign-In Widget, version 7.47.1

    For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.

    Agent-to-agent audience update

    The agent-to-agent server resource url (audience parameter) can now be a free-form string.

    Device Visibility feature for macOS and Windows

    Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.

    Original source
  • Jul 16, 2026
    • Date parsed from source:
      Jul 16, 2026
    • First seen by Releasebot:
      Jul 16, 2026
    Okta logo

    Privileged Access Platform by Okta

    Version: 2026.07.2

    Privileged Access Platform adds secret moving and keeps SaaS and Okta service accounts available during rotation failures.

    The following releases are now in Production:

    Move secret (EA)

    Users can now move a secret to a different folder to better align with their team's organizational structure. See Move a secret.

    Saas and Okta service accounts available during rotation failures

    If the password for SaaS or Okta service accounts fails to rotate, the account status remains Available. This change ensures continued access with the existing password while rotation issues are resolved.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Okta and hundreds of other software products.

    Create account
  • Jul 13, 2026
    • Date parsed from source:
      Jul 13, 2026
    • First seen by Releasebot:
      Jul 15, 2026
    • Modified by Releasebot:
      Jul 16, 2026
    Okta logo

    Okta Identity Engine by Okta

    2026.07.1

    Okta Identity Engine adds AI agent imports from Microsoft 365, new Anthropic (Claude) SAML SSO, and provisioning updates for Linear and Appspace, plus expanded Android device assurance support.

    Import AI agents from Microsoft Office 365

    You can now import and manage AI agents built in Microsoft Copilot Studio and Microsoft AI Foundry directly through Okta. See AI agent imports.

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • Android 13, 14, 15, 16 security patch 2026-01-05

    Anthropic (Claude) SAML SSO integration

    A new SAML 2.0 SSO integration for Anthropic (Claude) is now in the Okta Integration Network. This integration includes the existing Anthropic AI Agent. This feature is available to customers who have Okta for AI Agents. See Integrate Claude with Okta.

    Provisioning for Linear

    Linear provisioning is now available. See Create Linear integration.

    Provisioning for Appspace

    Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.

    Original source
  • Jul 13, 2026
    • Date parsed from source:
      Jul 13, 2026
    • First seen by Releasebot:
      Jul 14, 2026
    Okta logo

    Okta Classic Engine by Okta

    Okta Classic Engine 2026.07.1

    Okta Classic Engine adds provisioning for Linear and Appspace, including security features like Entitlement Management.

    2026.07.1: Update 1 started deployment on July 13

    Provisioning for Linear

    Linear provisioning is now available. See Create Linear integration.

    Provisioning for Appspace

    Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.

    Original source
  • Jul 9, 2026
    • Date parsed from source:
      Jul 9, 2026
    • First seen by Releasebot:
      Jul 10, 2026
    Okta logo

    Privileged Access Platform by Okta

    Version: 2026.07.1

    Privileged Access Platform adds Preview support for moving secrets to different folders to match team organization.

    The following releases are now in Preview:

    Move secret (EA)

    Users can now move a secret to a different folder to better align with their team's organizational structure. See Move a secret.

    Original source
  • Similar to Okta with recent updates:

  • Jul 7, 2026
    • Date parsed from source:
      Jul 7, 2026
    • First seen by Releasebot:
      Jul 7, 2026
    Okta logo

    Okta Identity Engine by Okta

    2026.07.0

    Okta Identity Engine adds broader AI agent management, device assurance, and access request updates, with new support for AI agent imports, roles, event hooks, and secure token exchange. It also expands provisioning, group and certificate controls, plus new OS support and threat protection improvements.

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • Android 13, 14, 15, 16 security patch 2026-01-05

    Spec-compliant client ID claims for AI agent tokens

    Okta Expression Language profiles now include the app.clientId property during user claim evaluations for AI agent OAuth 2.0 clients. This allows developers to generate spec-compliant tokens during AI agent flows.

    OAuth secure token exchange for Salesforce requests

    Okta for AI Agents now uses the OAuth 2.0 secure token exchange flow when it sends requests to the Salesforce app integration, resource server, or MCP server.

    AI agent events are now event-hook eligible

    The AI agent and AI agent provider events are now event-hook eligible, enabling Workflows to be triggered based on events. See Event hooks.

    Provisioning for Rapid7 InsightAppSec

    Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.

    Reassign steps to multiple users

    You can now reassign steps within an approval sequence or request type to 10 users. This applies to tasks, questions, actions, and approvals.

    Admin OIDC App Phase Two Tranch One

    When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.

    Sign-In Widget, version 7.46.2

    For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.

    Unique client authorization settings required for OIN apps

    When you enter client authorization details for an app integration, an error now appears if another integration already uses those details.

    New protocol runtime for Amazon Bedrock AgentCore AI agents

    You can now import both standard HTTP and agent-to-agent protocol runtimes from the Amazon Bedrock AgentCore platform.

    MCP servers active by default

    Newly created MCP servers are now in an active state by default. See Add MCP servers.

    AI agent admin role

    Super admins can now delegate AI agent management tasks using the new AI agent admin role. Admins with this role can perform tasks like registering AI agents, assigning owners, and configuring resource connections. See Manage Okta for AI Agents admin roles.

    Date range filter for AI agents

    The AI Agents page now provides a date range filter so admins can filter AI agents by when they were created or updated.

    Import AI agents from Google Vertex AI

    You can now import and manage AI agents built in Google Vertex AI directly through Okta. See Configure Google Vertex AI for AI agent imports.

    Sign-In Widget, version 7.46.3

    For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • Android 17 (2026-06-01)
    • Windows 10 builds (10.0.17763.8880, 10.0.19044.7417, 10.0.19045.7417)
    • Windows 11 builds (10.0.22631.7219, 10.0.26100.8655, 10.0.26200.8655)

    UI updates to Okta Access Requests web app

    The All requests page in the Okta Access Requests web app now shows 999+ count if there are 1000 or more requests instead of giving the count. This change helps reduce the time taken to list the requests on the page.

    Import Azure Active Directory users with null first and last name

    You can now import users from Microsoft Azure Active Directory (AAD) who have null first name and last name values. This provides admins with a centralized view of their AAD users within Okta. See Import users to Office 365 using Microsoft Graph API.

    Removal of search filters from the Inbox page

    The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.

    Okta for AI Agents UI updates

    The AI agents page now provides Owner and Platform filters. Also, the AI agent providers page now has Registered AI agents column that displays the number of AI agents that are registered from the provider.

    Suspicious Login Using A Sprayed Password

    This detection indicates that a user's password has been identified in a password spray campaign and used to successfullly sign in. The detection enables ITP to trigger configured remediation actions such as Universal Logout or password reset through a workflow. See Suspicious login using a sprayed password.

    This feature is following a slow rollout process.

    Bot protection

    Bot protection enables orgs to automatically identify and mitigate bot traffic by configuring remediation actions within the Identity Threat Protection (ITP) landing page. See Bot protection.

    New VPN service for enhanced dynamic zones

    The VIGOR_SSL_VPN is now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

    AI agents admin role help link

    On the Administrators Roles tab, the AI agents admin role now has a help link.

    Maximum number of IDPs in an IDP routing rule increased

    The maximum number of allowed IdPs in an IdP routing rule has been increased to 100. See Configure identity provider routing rules.

    Advanced posture checks for device assurance

    Advanced posture checks let admins configure specific device security conditions beyond what standard device assurance policies support. Using osquery, you can write custom SQL queries to assess device state on macOS and Windows devices, configure checks for unmanaged devices, and integrate with endpoint detection and response (EDR) tools. See Configure advanced posture checks for device assurance.

    Okta SSF Transmitter now available to CIAM orgs

    Okta uses CAEP to send security-related events and other data-subject signals to third-party security vendors. See Shared Signals Framework.

    This feature is now available to Customer Identity and Access Management orgs.

    Improved MFA enrollment policy validator

    Orgs that have no self-initiated user.account.update_password syslog events over last 30 days are now excluded from the MFA enrollment policy validator warning triggered during the Okta Identity Engine upgrade, making it easier to upgrade.

    Clear Managed Chrome Profile Browsing Data

    Clear Managed Chrome Profile Browsing Data provides real-time remediation by instantly purging local session data (cookies and cache) within managed Chrome profiles upon ITP detection. By transforming the browser into a policy-enforced workspace, it ensures immediate, automated protection. See Clear managed Chrome profile browsing data.

    Import unlicensed users from Azure Active Directory to Okta

    You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.

    Role-assignable push groups for Office 365

    When you create a new push group for the Office 365 app integration, select the Is this role assignable checkbox to make the group role assignable in Microsoft Entra ID. This allows you to push Okta groups to Microsoft Entra ID and assign roles instead of manually creating groups in Entra ID and then linking them to Okta using push groups. See Configure Push Group.

    Group push support in API Integration Actions apps

    Apps that use API Integration Actions to perform provisioning can now use the Group Push feature. This enables the group import functionality for apps that use group API contracts in their provisioning actions.

    Native to Web SSO

    Native to Web SSO creates a seamless, unified authentication experience when a user transitions from an OIDC app (like a native or web app) to a web app (either OIDC or SAML). This feature uses standard, web-based federation protocols like SAML and OpenID Connect that help bridge the gap between two different application environments, using a single-use, one-way interclient trust SSO token. This eliminates repeating already provided sign-on assurances, and simplifies development by reducing authentication complexity. See Configure Native to Web SSO.

    DirSync group imports for Active Directory

    For Active Directory (AD) integrations, the Provisioning tab now provides an Enable imports with AD using DirSync checkbox. When you enable the checkbox, admins can perform incremental group imports using DirSync. See Configure Active Directory import and account settings.

    ITP detections for AMFA orgs

    Adaptive MFA orgs now benefit from ITP detections on sessions and entity users when these are detected on directly assigned super admins. These detection events are actionable using Workflows. This feature aligns with the Okta Secure Identity Commitment. See Identity Threat Protection events in System Log.

    This feature is now available to Okta for US Military customers.

    On-demand rotation of Office 365 SSO signing certificates

    Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.

    Update group rule assignments

    Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.

    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 7, 2026
    Okta logo

    Okta Classic Engine by Okta

    Okta Classic Engine 2026.07.0

    Okta Classic Engine releases broader provisioning and access management updates, including new app provisioning for Rapid7 InsightAppSec and SAP BTP, easier Azure AD imports, faster Access Requests and Inbox performance, and new admin tools for group rules, push groups, MFA validation, and Office 365 certificates.

    Version: 2026.07.0

    Provisioning for Rapid7 InsightAppSec

    Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.

    Reassign steps to multiple users

    You can now reassign steps within an approval sequence or request type to 10 users. This applies to tasks, questions, actions, and approvals.

    Provisioning for SAP BTP

    Provisioning is now available for the SAP BTP app integration. When you provision the app, you can enable security features like Entitlement Management.

    Admin OIDC App Phase Two Tranch One

    When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.

    UI updates to Okta Access Requests web app

    The All requests page in the Okta Access Requests web app now shows 999+ count if there are 1000 or more requests instead of giving the count. This change helps reduce the time taken to list the requests on the page.

    Import Azure Active Directory users with null first and last name

    You can now import users from Microsoft Azure Active Directory (AAD) who have null first name and last name values. This provides admins with a centralized view of their AAD users within Okta. See Import users to Office 365 using Microsoft Graph API.

    Removal of search filters from the Inbox page

    The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.

    New VPN service for enhanced dynamic zones

    The VIGOR_SSL_VPN is now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

    Improved MFA enrollment policy validator

    Orgs that have no self-initiated user.account.update_password syslog events over last 30 days are now excluded from the MFA enrollment policy validator warning triggered during the Okta Identity Engine upgrade, making it easier to upgrade.

    Import unlicensed users from Azure Active Directory to Okta

    You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.

    Role-assignable push groups for Office 365

    When you create a new push group for the Office 365 app integration, select the Is this role assignable checkbox to make the group role assignable in Microsoft Entra ID. This allows you to push Okta groups to Microsoft Entra ID and assign roles instead of manually creating groups in Entra ID and then linking them to Okta using push groups. See Configure Push Group.

    Group push support in API Integration Actions apps

    Apps that use API Integration Actions to perform provisioning can now use the Group Push feature. This enables the group import functionality for apps that use group API contracts in their provisioning actions.

    DirSync group imports for Active Directory

    For Active Directory (AD) integrations, the Provisioning tab now provides an Enable imports with AD using DirSync checkbox. When you enable the checkbox, admins can perform incremental group imports using DirSync. See Configure Active Directory import and account settings.

    On-demand rotation of Office 365 SSO signing certificates

    Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.

    Update group rule assignments

    Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.

    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 6, 2026
    Okta logo

    Okta Identity Engine by Okta

    Version: 2026.07.0

    Okta Identity Engine adds AI agent, device assurance, and admin experience updates, including new AI agent roles and imports, stronger token and certificate controls, expanded OS support, advanced posture checks, improved MFA and group rule management, and user and email settings enhancements.

    Version: 2026.07.0

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • Android 13, 14, 15, 16 security patch 2026-01-05

    Spec-compliant client ID claims for AI agent tokens

    Okta Expression Language profiles now include the app.clientId property during user claim evaluations for AI agent OAuth 2.0 clients. This allows developers to generate spec-compliant tokens during AI agent flows.

    OAuth secure token exchange for Salesforce requests

    Okta for AI Agents now uses the OAuth 2.0 secure token exchange flow when it sends requests to the Salesforce app integration, resource server, or MCP server.

    AI agent events are now event-hook eligible

    The AI agent and AI agent provider events are now event-hook eligible, enabling Workflows to be triggered based on events. See Event hooks.

    Provisioning for Rapid7 InsightAppSec

    Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.

    Admin OIDC App Phase Two Tranch One

    When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.

    Unique client authorization settings required for OIN apps

    When you enter client authorization details for an app integration, an error now appears if another integration already uses those details.

    New protocol runtime for Amazon Bedrock AgentCore AI agents

    You can now import both standard HTTP and agent-to-agent protocol runtimes from the Amazon Bedrock AgentCore platform.

    MCP servers active by default

    Newly created MCP servers are now in an active state by default. See Add MCP servers.

    AI agent admin role

    Super admins can now delegate AI agent management tasks using the new AI agent admin role. Admins with this role can perform tasks like registering AI agents, assigning owners, and configuring resource connections. See Manage Okta for AI Agents admin roles.

    Date range filter for AI agents

    The AI Agents page now provides a date range filter so admins can filter AI agents by when they were created or updated.

    Import AI agents from Google Vertex AI

    You can now import and manage AI agents built in Google Vertex AI directly through Okta. See Configure Google Vertex AI for AI agent imports.

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • Android 17 (2026-06-01)
    • Windows 10 builds (10.0.17763.8880, 10.0.19044.7417, 10.0.19045.7417)
    • Windows 11 builds (10.0.22631.7219, 10.0.26100.8655, 10.0.26200.8655)

    Removal of search filters from the Inbox page

    The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.

    Okta for AI Agents UI updates

    The AI agents page now provides Owner and Platform filters. Also, the AI agent providers page now has Registered AI agents column that displays the number of AI agents that are registered from the provider.

    Suspicious Login Using A Sprayed Password

    This detection indicates that a user's password has been identified in a password spray campaign and used to successfullly sign in. The detection enables ITP to trigger configured remediation actions such as Universal Logout or password reset through a workflow. See Suspicious login using a sprayed password. This feature is following a slow rollout process.

    New VPN service for enhanced dynamic zones

    The VIGOR_SSL_VPN is now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

    AI agents admin role help link

    On the Administrators Roles tab, the AI agents admin role now has a help link.

    Strong cipher enforcement for X.509 client certificate authentication

    Okta now enforces strong cryptographic ciphers for X.509 client certificates used in mTLS authentication. Client certificates signed with weak ciphers, such as RSA-1024, are no longer accepted for new orgs. If you use X.509 certificate-based authentication, ensure that your client certificates meet FIPS 140-2 cipher requirements.

    Customizable emails for Passkeys (FIDO2 WebAuthn) authenticator

    The email that users receive when the admin configures a Passkeys (FIDO2 WebAuthn) authenticator is now available as a customizable template in Customizations Brands Emails. Admins can modify the subject line, email body, and dynamic variables such as the PIN, first name, and org name, and can add content in multiple languages.

    Email auto-enrollment and recovery management

    Admins can control the automatic enrollment of email as an authenticator and configure email-based password recovery, unlock, and change where email is not an authenticator. See Make email an optional authenticator.

    Advanced posture checks for device assurance

    Advanced posture checks let admins configure specific device security conditions beyond what standard device assurance policies support. Using osquery, you can write custom SQL queries to assess device state on macOS and Windows devices, configure checks for unmanaged devices, and integrate with endpoint detection and response (EDR) tools. See Configure advanced posture checks for device assurance.

    Update group rule assignments

    Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.

    Improved MFA enrollment policy validator

    Orgs that have no self-initiated user.account.update_password syslog events over last 30 days are now excluded from the MFA enrollment policy validator warning triggered during the Okta Identity Engine upgrade, making it easier to upgrade.

    Import unlicensed users from Azure Active Directory to Okta

    You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.

    Group push support in API Integration Actions apps

    Apps that use API Integration Actions to perform provisioning can now use the Group Push feature. This enables the group import functionality for apps that use group API contracts in their provisioning actions.

    ITP detections for AMFA orgs

    Adaptive MFA orgs now benefit from ITP detections on sessions and entity users when these are detected on directly assigned super admins. These detection events are actionable using Workflows. This feature aligns with the Okta Secure Identity Commitment. See Identity Threat Protection events in System Log. This feature is now available to Okta for US Military customers.

    On-demand rotation of Office 365 SSO signing certificates

    Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.

    Direct End-User Settings access

    Users may now access their Settings page through a direct URL in addition to the End-User Dashboard. This feature provides convenience and security for users, gives admins greater flexibility when working with End-User Dashboard access control scenarios, and includes accessibility and UX improvements. See End-User Settings.

    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 6, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.07.0

    Okta Identity Governance adds new governance controls for access reviews, including self-review options for admin roles, finer justification requirements, Workflows actions for request types, and certifications for service accounts and AI agent resource connections. It also improves Access Requests performance and UI.

    Features and Enhancements

    Self-review for Okta admin roles is Generally Available in Production environments

    Allow or block campaign reviewers from approving or revoking their own access to Okta admin roles. While Okta prevents self-reviews in campaigns that govern Okta admin roles by default, this feature gives you the option to allow self-reviews. See Create campaigns to review admin roles.

    Customize Justification Requirements is Generally Available in Production environments

    Configure Justification Settings when you create or edit a campaign to get more granular control over when campaign reviewers must enter a justification for access decisions, including making it mandatory only for revoke decisions and optional for approve decisions. This helps you better align the reviewer experience with your org's specific compliance needs. See Create resource campaigns or Create identity campaign.

    Okta Workflows actions for request types is Generally Available in Preview environments

    Use the Run a workflow action step in a request type to allow requests managed by request types to trigger a delegated flow automatically. The requestID of the request is passed to the delegated flow using the Okta Workflows Caller input field. This feature lets you use your existing Workflows connectors and flows in Access Requests to automate requests. See Create request type.

    Certify service accounts is Generally Available in Preview environments

    You can now create resource campaigns to review and certify access for both SaaS application and Okta service accounts. This feature extends your governance strategy to non-human identities, helping you maintain visibility and control over critical service account access. See Certify service accounts.

    Certify AI agent resource connections

    After you enable the Resource Access Certifications for AI Agents feature, you can review and certify AI agent resource connections using identity campaigns (formerly, user campaigns). This helps you maintain visibility and control as AI agents' access changes over time. See Create identity campaigns to certify resource connections.

    This is an Early Access release. See Enable self-service features.

    Removal of search filters from the Inbox page

    The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.

    UI updates to Okta Access Requests web app

    The All requests page in the Okta Access Requests web app now shows 999+ if there are 1,000 or more requests instead of showing the exact count. This change helps reduce the time taken to list the requests on the page.

    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 6, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.06.3

    Okta Identity Governance fixes the Past Access Requests report to stop showing older requests as recently modified.

    Fixes

    • The Past Access Requests (Request Types) report incorrectly displayed older access requests as recently modified. (OKTA-1185421)
    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 6, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.06.2

    Okta Identity Governance adds cancel action steps in requests, supports reassigning steps to up to 10 users, and fixes admin role approvals.

    Features and Enhancements

    Cancel action steps in requests managed by request types

    If an action step is stuck in a request managed by a request type, request assignees can cancel the action step to better manage the request.

    Reassign steps to multiple users

    You can now reassign steps within an approval sequence or request type to 10 users. This applies to tasks, questions, actions, and approvals.

    Fixes

    • Sometimes approval tasks in access requests for Okta admin roles weren't assigned to groups and remained unassigned, causing delays in request resolution. (OKTA-1198387)
    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 6, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.06.0

    Okta Identity Governance releases Smart Review for campaign reviewers, new access certification reporting, Governance Analyzer, self-review controls for admin roles, justification settings, and usability and limits improvements across requests and task assignment.

    Features and Enhancements

    Smart Review for campaign reviewers is Generally Available in Production environments

    Smart Review creates a step-by-step workflow for campaign reviewers that groups items by user or resource. This approach helps reduce reviewer fatigue, enables more informed access decisions, and helps reviewers efficiently tackle high-volume campaigns. See Smart review.

    Assignment methods for access certification campaigns is Generally Available in Production environments

    The Assignment methods setting gives access certification campaign reviewers context on how a user was assigned access to a resource. It provides visibility into assignment methods for all resources, including all methods used to grant entitlements. This feature helps reviewers make informed, accurate decisions about a user's access. See Customizable reviewer context.

    With this feature, the following Admin Console changes are also applicable:

    • The existing Assignment type field has been renamed to Assignment methods.
    • The existing Application assignment type field has been renamed to Application assignment methods.
    • Resource-specific assignment method fields, such as Assigned via policy, Collection assignment type, Entitlement assignment type, and Group assignment type are no longer available. The information appears in the Assignment methods field.

    The assignment method value Custom has been renamed to Individual. See Assignment methods.

    Active Campaign Summary report is Generally Available in Production environments

    Use this report to view the high-level configurations and status of your active access certification campaigns. This overview helps you easily track overall campaign progress at a glance. See Active Campaign Summary report.

    Active Campaign Details report is Generally Available in Production environments

    Use this report to view in-depth information about your active access certification campaigns. This detailed view helps you monitor granular progress, identify reviewers who haven't completed their tasks, and improve overall completion rates. See Active Campaign Details report.

    Governance Analyzer is Generally Available in Preview environments

    Governance Analyzer provides access certification campaign reviewers with insights and recommendations to make more informed decisions when approving or revoking user access. See Governance analyzer.

    Self-review for Okta admin roles is Generally Available in Preview environments

    Allow or block campaign reviewers from approving or revoking their own access to Okta admin roles. While Okta prevents self-reviews in campaigns that govern Okta admin roles by default, this feature gives you the option to allow self-reviews. See Create campaigns to review admin roles.

    Customize Justification Requirements is Generally Available in Preview environments

    Configure Justification Settings when you create or edit a campaign to get more granular control over when campaign reviewers must enter a justification for access decisions, including making it mandatory only for revoke decisions and optional for approve decisions. This helps you better align the reviewer experience with your org's specific compliance needs. See Create resource campaigns or Create user campaign.

    This feature is Generally Available in Preview environments, but it's an Early Access release for Production environments.

    Improved request details layout

    The request details page now features an optimized layout for small screens to improve readability.

    Increased maximum for groups in access levels

    You can now specify a maximum of 500 unique groups when you define the Access level for an access request condition. Consequently, the maximum number of options available to requesters for an app is 50,000. See Access request condition limits.

    Improved task assignment logic for group owners

    When a group has a mix of individual users and groups defined as its group owner, Okta now assigns access request tasks to both the individual users and the members of the owner group.

    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 6, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.05.3

    Okta Identity Governance fixes access certification campaign emails that stayed in English despite user locale settings.

    Fixes

    • All access certification campaign notification emails were in English even when a different Locale was specified on the user's profile page in the Admin Console. (OKTA-1170541)
    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 6, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.05.2

    Okta Identity Governance adds a new System Log access.request.update event and fixes an owner link error in app governance.

    Features and enhancements

    New System Log event

    The access.request.update event is fired when an update is made to the tasks in a request, such as task assignment or completion. See Event types.

    Fixes

    • After an admin assigned an owner on an app's Governance tab, clicking the owner's link on the Owners tab resulted in an error. (OKTA-1170538)
    Original source
  • July 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Jul 6, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.05.0

    Okta Identity Governance adds Governance Analyzer, Smart Review, assignment method context, and new campaign reports to improve access certification decisions, plus access request condition descriptions and admin console updates. It also fixes campaign review issues.

    Features and Enhancements

    Governance Analyzer

    Governance Analyzer provides access certification campaign reviewers with insights and recommendations to make more informed decisions when approving or revoking user access. See Governance analyzer.

    This is an Early Access release. See Enable self-service features.

    Self-review for Okta admin roles

    Allow or block campaign reviewers from approving or revoking their own access to Okta admin roles. While Okta prevents self-reviews in campaigns that govern Okta admin roles by default, this feature gives you the option to allow self-reviews. See Create campaigns to review admin roles.

    This is an Early Access release. See Enable self-service features.

    Smart Review for campaign reviewers is Generally Available in Preview environments

    Smart Review creates a step-by-step workflow for campaign reviewers that groups items by user or resource. This approach helps reduce reviewer fatigue, enables more informed access decisions, and helps reviewers efficiently tackle high-volume campaigns. See Smart review.

    Assignment methods for access certification campaigns is Generally Available in Preview environments

    The Assignment methods setting gives access certification campaign reviewers context on how a user was assigned access to a resource. It provides visibility into assignment methods for all resources, including all methods used to grant entitlements. This feature helps reviewers make informed, accurate decisions about a user's access. See Customizable reviewer context.

    With this feature, the following Admin Console changes are also applicable:

    • The existing Assignment type field has been renamed to Assignment methods.
    • The existing Application assignment type field has been renamed to Application assignment methods.
    • Resource-specific assignment method fields, such as Assigned via policy, Collection assignment type, Entitlement assignment type, and Group assignment type are no longer available. The information appears in the Assignment methods field.

    The assignment method value Custom has been renamed to Individual. See Assignment methods.

    Active Campaign Summary report is Generally Available in Preview environments

    Use this report to view the high-level configurations and status of your active access certification campaigns. This overview helps you easily track overall campaign progress at a glance. See Active Campaign Summary report.

    Active Campaign Details report is Generally Available in Preview environments

    Use this report to view in-depth information about your active access certification campaigns. This detailed view helps you monitor granular progress, identify reviewers who haven't completed their tasks, and improve overall completion rates. See Active Campaign Details report.

    Add access request condition descriptions

    You can now add descriptions to access request conditions for apps, collections, and Okta admin role bundles. These descriptions appear alongside the condition's name on the Access Requests tab, making it easier for you to understand the specific purpose of each condition. See Create access request conditions.

    Admin Console updates for Past Campaign Details and Past Campaign Summary reports

    The following column headers have been renamed in the Past Campaign Details and Past Campaign Summary reports:

    • Campaign started is now called Campaign start date.
    • Campaign ended is now called Campaign end date.

    Admin Console updates for access certification campaigns

    • The Select applications dropdown menu on the campaign wizard's Resources page for AI agent resource types has been updated for clarity.
    • The Managed connections checkbox on the Contextual Information page and the Managed connections field on the Review details panel have been renamed to Resource connections.

    Fixes

    • Apps that didn't have any entitlements weren't listed as a review item in user campaigns. (OKTA-1120669)
    • Manual remediation was required when reviewers revoked a user's access to Active Directory-source groups in a campaign. (OKTA-1167090)
    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.