Okta Release Notes

Follow

119 release notes curated from 6 sources by the Releasebot Team. Last updated: Sep 12, 2026

Get this feed:

Okta Products

  • Sep 12, 2026
    • Date parsed from source:
      Sep 12, 2026
    • First seen by Releasebot:
      Sep 12, 2026
    Okta logo

    Okta Identity Engine by Okta

    Version: 2026.09.0

    Okta Identity Engine releases a broad September-style update with MCP server registration, device assurance and dynamic zone enhancements, new passkey and device-bound SSO options, expanded provisioning and access limits, plus admin console, security, and integration improvements.

    Okta Identity Engine release notes (Preview)

    Generally Available

    Version: 2026.09.0

    Okta Integration Network MCP server registration

    You can now add MCP servers from an Okta Integration Network catalog entry, without entering its connection details manually. See Add an MCP server from the OIN catalog. This feature is following a slow rollout with preview deployment throughout mid-September, followed by production.

    Dynamic Client Registration support for MCP server registration

    Admins can now select Dynamic Client Registration (DCR) when manually registering an MCP server. When you select this option, Okta automatically registers a client with the provider and populates the credentials. See Manually add MCP servers. This feature is following a slow rollout with preview deployment throughout mid-September, followed by production.

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies: * Android 14, 15, 16, 17 (2026-08-01)

    New IP service categories for enhanced dynamic zones

    Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • macOS 14.8.9
    • macOS 15.7.9
    • macOS 26.6.1

    Okta On-Prem MFA agent version 1.8.7

    This version includes security enhancements.

    UI updates for AI agent client registration

    On the AI agent > Client registration tab, the authentication methods are now displayed vertically and provide a Configure button. When you click Configure, you're directed to a configuration page for the authentication method.

    Task count optimization

    To improve performance in the Admin Console, the Tasks page now displays an approximate count of 999+ when a task contains more than 1,000 items.

    Radius Agent version 2.27

    This version includes internal improvements and fixes.

    Copy email from-addresses to the default brand domain

    You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • macOS (26.6.2)
    • iOS (26.6.1, 18.7.10)
    • Windows 10 builds (10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663)
    • Windows 11 builds (10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168)

    Authentication requirement for AI agent app

    When an AI agent is bound to an app, the User access tab now displays the authentication requirement for the app. It also provides a link to the app's Sign On tab where you can configure an authentication policy.

    JAMF Pro integration updates

    The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM userName attribute.

    Improved MCP server registration UI

    MCP server registration has been updated with improved UI for scope handling and tool visibility.

    Okta Provisioning Agent, version 3.3.1

    Okta Provisioning Agent 3.3.1 is now available. This release updates the bundled JDK patch version and includes security enhancements. See Okta Provisioning Agent and SDK version history.

    Provisioning for WordPress

    Provisioning is now available for the WordPress integration. See Integrate WordPress with Okta.

    Provisioning for Ivanti

    Provisioning is now available for the Ivanti integration. See Integrate Ivanti with Okta.

    Provisioning for Progress Chef

    Provisioning is now available for the Progress Chef integration. See Integrate Progress Chef with Okta.

    SAP Connector

    The SAP integration has been migrated to use the SCIM 2.0 API, and the connector's internal HTTP helper has been updated to support this standard.

    DBSSO device probing improvement

    DBSSO now relies on the device-registered conditions that are configured in an app's sign-on policy instead of using org-wide probing methods.

    Remote Desktop detection

    Admins can now detect and control access from remote desktops using a new REMOTE_DESKTOP IP service category in Enhanced Dynamic Network Zones. Admins can include or exclude REMOTE_DESKTOP when configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these networks. See Supported IP service categories.

    Passkey enrollment promotion prompt

    You can now configure a passkey enrollment promotion nudge that prompts end users to enroll a passkey authenticator when they sign in. The nudge applies only when the passkey authenticator is optional, and users who skip it can still sign in with another authenticator. You can control how often the prompt reappears and how many times a user can skip it before Okta stops showing it. See Create an authenticator enrollment policy.

    Email notifications for disrupted AD and LDAP agents

    System email notifications now include options for Active Directory and LDAP agent disruption and recovery. Admins can enable notifications in the Admin Console to receive email alerts when an agent disrupts and recovers.

    Provisioning for Vercel

    Provisioning is now available for the Vercel integration. See Integrate Vercel with Okta.

    Increased Access Request limit

    The following Access Request limits have been increased:

    • Users per task or question: 25 (previously 10)
    • Entitlement bundles in an access level condition: 1,000 (previously 100)
    • Groups in an access level condition: 1,000 (previously 500)
    • Request type configuration lists per org: 250 (previously 100)
    • Request types per org: 750 (previously 500)

    Tool discovery for MCP servers

    When you register an MCP server, you can now test your credentials and discover its available tools. This ensures your connections are fully verified and lets you view the MCP server's capabilities. See Add MCP servers.

    Platform SSO password integration with Device-Bound SSO

    The Platform SSO password authentication method now integrates with Device-Bound SSO. When a user signs in at the macOS sign-in window, Okta verifies the password factor and creates a device-bound session. Users can then access Okta-protected apps in their browser without additional password prompts. See Platform SSO for macOS and Configure device configuration profiles for PSSO using a generic MDM.

    Secure Enclave key support for Platform SSO

    Platform SSO now supports a Secure Enclave key-based authentication method that integrates with Device-Bound SSO. When a user authenticates at the macOS sign-in window with their password, the authentication unlocks a hardware-bound cryptographic key stored in the Secure Enclave. Okta uses the key to create a device-bound session that satisfies any authentication policy that requires Okta FastPass with user verification, without repeated MFA prompts. See Platform SSO for macOS and Configure device configuration profiles for Secure Enclave using a generic MDM.

    Device-Bound Single Sign-On

    Device-Bound Single Sign-On initiates a hardware-protected session for seamless access to apps after users sign in to Okta-joined macOS and Windows devices. This feature provides session replay protection and a streamlined authentication experience. See Device-Bound Single Sign-On.

    PowerShell scripts for Active Directory

    Admins can now execute custom PowerShell scripts in on-premises Active Directory environments using the Active Directory agent to support custom lifecycle management functionalities. After configuration, admins can invoke scripts through Okta Workflows using the Okta public API. See Enable and configure PowerShell script in Active Directory and Invoke a remote script on the AD agent.

    Early Access

    Desktop MFA Factor Discovery for Windows

    Desktop MFA for Windows now shows users only the MFA factors they've enrolled, instead of a fixed list of all available factors. New users without an enrolled factor can sign in during their grace period to set up MFA, while existing users signing in on a new device must verify with an existing factor. See Enable Desktop MFA Factor Discovery.

    Okta On-prem SCIM Server agent is now Okta On-prem SCIM agent

    Okta On-prem SCIM Server agent has been replaced by Okta On-prem SCIM agent. This change reduces the number of dependencies and allows for new features to be implemented. See On-prem Connector for Generic Databases.

    Realm assignment limit increase

    The maximum number of realm assignments allowed per profile source has been increased from 30 to 100. This enables admins to scale user organization and management across a larger number of realms. See Realms.

    NFC authenticator

    Okta now supports an NFC authenticator as an authentication method for frontline workers signing in to Okta-protected apps on Windows desktop shared workstations. To authenticate, an end user taps their NFC badge on a reader and enters a PIN to meet MFA requirements, without needing a phone, password, or shared account. See NFC authenticator.

    Entitlement import safeguards

    Entitlement import safeguards prevent user imports from accidentally removing app roles or licenses when a user is unassigned from an app. Admins can configure safeguards per app using either percentage-based or absolute count thresholds, and optionally block imports that modify or delete entitlement schemas. See Import safeguards.

    Applications page enhancements

    The Applications page now provides options to filter apps by type and status, search apps by name or client ID, and view apps by last modified date. You can also export apps to CSV to turn your filtered list into an audit-ready report. During Early Access, labelling uses IGA Governance Labels and is only available for OIG customers. See Search, filter, and export app integrations and Resource labels.

    Low-Code Sign In Customization

    Customizations are a key concern for enterprises. Few things have as much impact on customer trust as the look and feel of their site branding. It's how users know to trust the site and learn about new offerings. With Low-Code Sign In Customization, admins can customize the text, colors, and images of their Sign-In Widget without the need for complicated or risky changes using the code editor. A JSON templating language with syntax highlighting and suggestions enable admins to make visual changes to the sign-in page and Interstitial authentication to match their desired experience without changing a line of code. See Customize your sign-in page.

    On-prem Connector for Generic Databases supports high availability using Unified OPS Agent

    The On-prem Connector for Generic Databases now supports high availability, which lets you assign multiple Okta On-Premises SCIM Agents to a single app instance so that any available agent can service an import or provisioning operation. This removes the single point of failure for on-premises database integrations and keeps them running while an individual agent is offline or being upgraded. See On-prem Connector for Generic Databases.

    On-prem Connector for Generic Databases supports incremental imports

    The On-prem Connector for Generic Databases now supports incremental imports, which retrieves only the users and entitlement assignments that have changed since the last successful import, rather than the full dataset. This reduces import duration and database load for large-scale deployments. The source database must use soft deletes and maintain an automatically updated timestamp column. See On-prem Connector for Generic Databases.

    Fixes

    • Push notifications for Okta Verify challenges during direct authentication sometimes failed with a direct_auth_policy_denied error when biometric verification wasn't enrolled. (OKTA-1099950)
    • Password policy errors related to breached credentials protection persisted after admins resolved the issues. (OKTA-1239168)
    • Some links on the Sign-In Help page didn't meet the minimum contrast ratio. (OKTA-1241201)
    • Newly imported Active Directory users couldn't activate their accounts through email links when out-of-band Okta Verify enrollment was enabled in the Okta account management policy. (OKTA-1250588)
    • When no passkeys were enrolled, the End-User Dashboard showed the security method label as Security Key or Biometric Authenticator instead of Passkey. (OKTA-1258336)
    • Some custom profile attributes were still visible in the UI after they were deleted by an admin. (OKTA-1260654)
    • When using Okta as a certificate authority (CA) instead of a third-party CA, the Okta CA didn't permit device re-registration after the device was deleted from Okta. (OKTA-1261907)
    • For AI agents with user sign-on delegations, the deprecation banner on the User access tab displayed incorrect information. (OKTA-1262867)
    • Custom admin roles could generate a Desktop MFA recovery PIN for users who weren't in their resource group if they had the device level recovery PIN permission. (OKTA-1264620)
    • When the Flexible Okta Verify authenticator configuration was enabled, end users who signed in to RADIUS apps with Okta Verify - Push received an error. (OKTA-1265932)

    Okta Integration Network

    • Harriet (SCIM) was updated. Learn more.
    • Your360 (OIDC) is now available. Learn more.
    • Your360 (SAML) is now available. Learn more.
    • Harriet (OIDC) was updated.
    • Sensor Tower (SCIM) is now available. Learn more.
    • Visily Lifecycle Management Connector By Redblock (SCIM) is now available. Learn more.
    • Instagram (SWA) was updated.

    Preview org features

    SAP SuccessFactors OAuth 2.0 with SAML Assertion

    The SAP SuccessFactors app integration now supports OAuth 2.0 with SAML Assertion for enhanced API security. To ensure your provisioning and sync processes continue without interruption, you must migrate to this new authentication method before the SAP Basic Authentication deletion deadline on November 20, 2026. See Configure OAuth 2.0 with SAML for SAP SuccessFactors.

    Workday supports incremental imports

    Workday now has the ability to run immediate, incremental imports. Incremental imports are much faster than full imports. However, they don't detect when users only have changes to custom attributes, so you must periodically run a full import to capture these changes. See Incremental imports.

    Same-device enrollment for Okta FastPass

    On orgs with Okta FastPass, the Okta Verify enrollment process has been streamlined:

    • Users can initiate and complete enrollment on the device they're currently using. Previously, two different devices were required to set up an account.
    • Users no longer need to enter their org URL during enrollment.
    • The enrollment flow has fewer steps. This feature is supported on Android, iOS, and macOS devices.

    Direct End-User Settings access

    Users may now access their Settings page through a direct URL in addition to the End-User Dashboard. This feature provides convenience and security for users, gives admins greater flexibility when working with End-User Dashboard access control scenarios, and includes accessibility and UX improvements. See End-User Settings.

    End-user setting for nicknaming factors

    End users can now nickname their phone, WebAuthn, and Okta Verify factors. If they have enrolled multiple instances of a factor, giving nicknames helps them identify the factors quickly (for example, "My personal cellphone" or "My office MacBook TouchID"). See the end-user documentation. This is a self-service feature.

    Descriptive System Log events

    When Okta identifies a security threat, the resulting security.threat.detected System Log entry now provides a descriptive reason for the event. See System Log.

    New flexible LDAP

    A new LDAP schema allows flexibility by moving email to the custom schema and making first name, last name, username, and UID optional. This avoids error scenarios when an LDAP schema doesn't include specific attributes.

    ThreatInsight coverage on core Okta API endpoints

    Okta ThreatInsight coverage is now available for core Okta API endpoints:

    • OpenID Connect and OAuth 2.0
    • Okta Management
    • MyAccount API

    Based on heuristics and machine learning models, Okta ThreatInsight maintains an evolving list of IP addresses that consistently show malicious activity across Okta's customer base. Requests from these bad IP addresses can be blocked or elevated for further analysis when Okta ThreatInsight is enabled for an Okta org. Previously, Okta ThreatInsight coverage only applied to Okta authentication endpoints (including enrollment and recovery endpoints). With this release, enhanced attack patterns are detected for authentication endpoints and limited attack patterns are also detected for non-authentication endpoints. There are no changes to the existing Okta ThreatInsight configuration. You can still enable Okta ThreatInsight with log and block mode, log mode, and exempt network zones. A new Negative IP Reputation reason is available for high security.threat.detected events. See System Log events for Okta ThreatInsight.

    Original source
  • September 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Sep 12, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.09.0

    Okta Identity Governance adds configurable resource catalog visibility, GA certification for AI agent resource connections, higher Access Request limits, and smoother Unified Requester Experience navigation. It also includes MCP server scope reviews in campaigns plus fixes for campaign inactivity and AD group assignment issues.

    Features and Enhancements

    Configure access to the resource catalog is Generally Available in Preview environments

    Previously, the ability to view resource catalog entry points, such as the Request Access button in the End-User Dashboard, was available to all users in an org by default. Now, admins can configure this visibility to allow all members of an org to view the entry points, no users to view them, or restrict entry point visibility to a specific set of Okta groups. For the Unified requester experience, this configuration also controls the Resource Catalog links and search options from the Okta Access Request app, Slack, and Microsoft Teams. See Configure resource catalog entry point visibility.

    Certify AI agent resource connections is Generally Available in Production environments

    You can review and certify AI agent resource connections using identity campaigns (formerly, user campaigns). This helps you maintain visibility and control as AI agents' access changes over time. See Create identity campaigns to certify resource connections.

    Increased Access Request limits

    The following Access Request limits have been increased:

    • Users per task or question: 25 (previously 10)
    • Entitlement bundles in an access level condition: 1,000 (previously 100)
    • Groups in an access level condition: 1,000 (previously 500)
    • Request type configuration lists per org: 250 (previously 100)
    • Request types per org: 750 (previously 500)

    Streamlined navigation for access requests

    For orgs with the Unified Requester Experience enabled, requesters who select a request type tile on the End-User Dashboard now go directly to the request form, speeding up the access request process. Requesters don't need to click the Request access link on an intermediary page.

    MCP server scopes in campaign reviews

    When you certify managed connections, OAuth 2.0 scopes are now included in the campaign review for MCP server connections.

    Fixes

    • Admins could set campaign inactivity periods to more than 90 days, which wasn't aligned with the System Log retention period. (OKTA-1254593)
    • Missing HTTP content headers caused AD group assignments and revocations to fail intermittently. (OKTA-1266481)
    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Okta and hundreds of other software products.

    Create account
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 12, 2026
    Okta logo

    Privileged Access Platform by Okta

    Version: 2026.09.1

    Privileged Access Platform adds workload roles for revealing and rotating Active Directory account passwords via API key auth.

    The following releases are now in Production:

    Reveal Active Directory account passwords with workload roles

    You can now use workload roles to reveal and rotate passwords for Active Directory accounts through API key authentication.

    Original source
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    Okta logo

    Okta Classic Engine by Okta

    2026.08.4

    Okta Classic Engine updates the SAP connector to use SCIM 2.0 API support for the SAP integration.

    SAP Connector

    The SAP integration has been migrated to use the SCIM 2.0 API, and the connector's internal HTTP helper has been updated to support this standard.

    Original source
  • September 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Sep 5, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.08.4

    Okta Identity Governance adds configurable visibility for resource catalog entry points, letting admins control who can see Request Access and related links. The setting can show them to everyone, no one, or selected Okta groups across the end-user dashboard and unified requester experience.

    Features and Enhancements

    Configure access to the resource catalog

    Previously, the ability to view resource catalog entry points, such as the Request Access button in the End-User Dashboard, was available to all users in an org by default. Now, admins can configure this visibility to allow all members of an org to view the entry points, no users to view them, or restrict entry point visibility to a specific set of Okta groups. For the Unified requester experience, this configuration also controls the Resource Catalog links and search options from the Okta Access Request app, Slack, and Microsoft Teams. See Configure resource catalog entry point visibility.

    Original source
  • Similar to Okta with recent updates:

  • Sep 3, 2026
    • Date parsed from source:
      Sep 3, 2026
    • First seen by Releasebot:
      Sep 5, 2026
    Okta logo

    Privileged Access Platform by Okta

    Version: 2026.09.0

    Privileged Access Platform adds preview Assignments to simplify privileged access management at scale.

    The following releases are now in Preview:

    Simplified privileged access management with Assignments (EA)

    Security admins can now use Assignments in Okta Privileged Access to streamline and manage access to privileged resources at scale. This relationship-aware model reduces redundant permission records by replacing thousands of static assignments with dynamic policies. See Assignments and relationships.

    Original source
  • Aug 31, 2026
    • Date parsed from source:
      Aug 31, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    Okta logo

    Okta Classic Engine by Okta

    2026.08.3

    Okta Classic Engine adds Jamf Pro integration updates with a default Application username format field for custom SCIM userName mappings.

    Jamf Pro integration updates

    The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM userName attribute.

    Original source
  • Aug 31, 2026
    • Date parsed from source:
      Aug 31, 2026
    • First seen by Releasebot:
      Sep 1, 2026
    Okta logo

    Okta Identity Engine by Okta

    2026.08.3

    Okta Identity Engine adds manual MCP server registration, expanded device assurance OS support, clearer AI agent app authentication requirements, and Jamf Pro integration updates that surface Application username format by default for custom SCIM userName mappings.

    2026.08.3: Update 3 started deployment on August 31

    Manual MCP registration

    Admins can now manually configure authorization server details and client credentials when registering MCP servers. This allows registration of internal or legacy MCP servers that don't support automated metadata discovery endpoints. See Add MCP servers.

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • macOS (26.6.2)
    • iOS (26.6.1, 18.7.10)
    • Windows 10 builds (10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663)
    • Windows 11 builds (10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168)

    Authentication requirement for AI agent app

    When an AI agent is bound to an app, the User access tab now displays the authentication requirement for the app. It also provides a link to the app's Sign On tab where you can configure an authentication policy.

    Jamf Pro integration updates

    The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM userName attribute.

    Original source
  • Aug 31, 2026
    • Date parsed from source:
      Aug 31, 2026
    • First seen by Releasebot:
      Sep 1, 2026
    Okta logo

    Privileged Access Platform by Okta

    Version: 2026.08.5

    Privileged Access Platform adds production-ready manual password configuration for resource credentials and expands preview features for bulk Active Directory password rotation and workload access control for secrets, helping admins simplify migration, streamline rotation, and strengthen least-privilege access.

    The following releases are now in Production:

    Manual password configuration for resource credentials

    You can now set passwords for Active Directory, SaaS, and Okta Universal Directory service accounts without triggering target system synchronization. This enhancement simplifies account migration and onboarding workflows while preserving continuous access to connected accounts.

    The following releases are now in Preview:

    Bulk password rotation for Active Directory accounts (EA)

    Admins can now force password rotation for up to 100 Active Directory accounts simultaneously within a project. This enhancement streamlines daily administrative workflows by eliminating the need to rotate individual account passwords manually. See Bulk rotate Active Directory passwords.

    Workload access control for secrets

    Security admins can now extend least-privilege access controls to machine identities by assigning workload roles to secret policies. This allows workloads to perform operations on secrets while generating individual workload audit logs for tracking.

    Original source
  • Aug 27, 2026
    • Date parsed from source:
      Aug 27, 2026
    • First seen by Releasebot:
      Aug 27, 2026
    Okta logo

    Privileged Access Platform by Okta

    Version: 2026.08.4

    Privileged Access Platform adds preview manual password configuration for resource credentials to simplify migration and onboarding.

    The following releases are now in Preview:

    Manual password configuration for resource credentials

    You can now set passwords for Active Directory, SaaS, and Okta Universal Directory service accounts without triggering target system synchronization. This enhancement simplifies account migration and onboarding workflows while preserving continuous access to connected accounts.

    Original source
  • Aug 25, 2026
    • Date parsed from source:
      Aug 25, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    Okta logo

    Okta Classic Engine by Okta

    2026.08.2

    Okta Classic Engine adds JA4 TLS fingerprinting, real-time import monitoring updates, and easier brand email setup with copy-from-address support, while also including internal improvements and fixes in Radius Agent 2.27.

    Radius Agent version 2.27

    This version includes internal improvements and fixes.

    JA4 TLS fingerprinting

    Okta now captures JA4 TLS client fingerprints across Syslog event types (securityContext.tlsFingerprint.ja4 pr), instead of just a curated subset. This includes telephony events (for example, OTP/SMS delivery) along with sign-in, auth, and token events. This provides customers and Okta's security teams with fingerprint-level visibility to spot bot traffic, toll fraud, and other TLS-based attack patterns that IP/user-agent signals miss on their own.

    This is not yet available for orgs on custom-hosted domains.

    Enhanced import monitoring with real-time updates

    You can now view real-time progress for imports from the Import Monitoring dashboard. This provides greater visibility into the current status of in-progress imports such as the number of data chunks currently being processed.

    Copy email from-addresses to the default brand domain

    You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.

    Original source
  • Aug 25, 2026
    • Date parsed from source:
      Aug 25, 2026
    • First seen by Releasebot:
      Aug 26, 2026
    • Modified by Releasebot:
      Sep 1, 2026
    Okta logo

    Okta Identity Engine by Okta

    2026.08.2

    Okta Identity Engine adds device assurance OS support, broader JA4 TLS fingerprinting, real-time import monitoring updates, and easier email from-address copying across brand domains, while Radius Agent 2.27 brings internal improvements and fixes.

    2026.08.2: Update 2 started deployment on August 25

    Device assurance OS version update

    The following OS versions are now supported in device assurance policies:

    • macOS 14.8.9
    • macOS 15.7.9
    • macOS 26.6.1

    Radius Agent version 2.27

    This version includes internal improvements and fixes.

    JA4 TLS fingerprinting

    Okta now captures JA4 TLS client fingerprints across Syslog event types (securityContext.tlsFingerprint.ja4 pr), instead of just a curated subset. This includes telephony events (for example, OTP/SMS delivery) along with sign-in, auth, and token events. This provides customers and Okta's security teams with fingerprint-level visibility to spot bot traffic, toll fraud, and other TLS-based attack patterns that IP/user-agent signals miss on their own.

    This is not yet available for orgs on custom-hosted domains.

    Enhanced import monitoring with real-time updates

    You can now view real-time progress for imports from the Import Monitoring dashboard. This provides greater visibility into the current status of in-progress imports such as the number of data chunks currently being processed.

    Copy email from-addresses to the default brand domain

    You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.

    Original source
  • Aug 25, 2026
    • Date parsed from source:
      Aug 25, 2026
    • First seen by Releasebot:
      Aug 22, 2026
    • Modified by Releasebot:
      Sep 1, 2026
    Okta logo

    Privileged Access Platform by Okta

    Version: 2026.08.3

    Privileged Access Platform adds Production support for static JWKS in JWT Workload Connectors and API key authentication for Okta Privileged Access workload identities, helping private and air-gapped admins secure secretless and legacy workload authentication.

    The following releases are now in Production:

    Static JWKS support for JWT Workload Connectors

    Admins operating in private or air-gapped environments can now configure a JWT Workload Connector using static JWKS content. This enables secretless workload authentication for high-security on-premises systems without requiring public key discovery endpoints. See Workloads.

    API key authentication for Okta Privileged Access workload identities

    Security admins can now create and manage API key connectors and issued secrets for workload identities. This allows legacy and non-OIDC workloads to authenticate securely to Okta Privileged Access. See Workloads.

    Original source
  • August 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Aug 22, 2026
    Okta logo

    Okta Identity Governance by Okta

    Release 2026.08.2

    Okta Identity Governance adds access request admin enhancements, letting admins view and cancel requests even with completed tasks. It also expands the Request Inbox in the Okta Access Requests app and includes fixes for rate limit reporting and campaign review display issues.

    Features and Enhancements

    Access request admin action enhancements

    Access request admins can now view and cancel requests, even if there are completed tasks associated with them.

    Request Inbox updates in the Okta Access Requests app

    Access request admins can now view all requests in the org from the Requests Inbox page.

    Fixes

    • The following endpoints weren't visible in the Rate limit report:
      • /governance/api/v1/my/campaigns/{campaignId}/reviews
      • /governance/api/v1/my/campaigns/{campaignId}/reviews/actions
      • /governance/api/v1/my/campaigns/{campaignId}/reviews/bulk-decisions
      • /governance/api/v1/my/campaigns/{campaignId}/reviews/bulk-decisions/jobs/{jobId}
        (OKTA-1211609)
    • The issuer URL value appeared in the Audience field of an AI agent connection campaign review instead of the resource indicator value. (OKTA-1239834)
    Original source
  • Aug 17, 2026
    • Date parsed from source:
      Aug 17, 2026
    • First seen by Releasebot:
      Aug 19, 2026
    Okta logo

    Okta Classic Engine by Okta

    2026.08.1: Update 1 started deployment on August 17

    Okta Classic Engine now supports several new IP service categories as individual VPN service categories in enhanced dynamic zones.

    Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones.

    See Supported IP categories.

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.