Okta Classic Engine Updates & Release Notes
18 updates curated from 1 source by the Releasebot Team. Last updated: Aug 19, 2026
- Aug 17, 2026
- Date parsed from source:Aug 17, 2026
- First seen by Releasebot:Aug 19, 2026
2026.08.1: Update 1 started deployment on August 17
Okta Classic Engine now supports several new IP service categories as individual VPN service categories in enhanced dynamic zones.
Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones.
See Supported IP categories.
Original source - August 2026
- No date parsed from source.
- First seen by Releasebot:Aug 14, 2026
2026.08.0
Okta Classic Engine releases broader provisioning and security updates, including AI agent imports from Workday, new provisioning for several apps, stronger Office 365 authentication and certificate management, and updates to agents, group rules, exports, and dynamic zones.
Version: 2026.08.0
Import AI agents from Workday
You can now import and manage AI agents built in the Workday Agent System of Record (ASOR) directly through Okta. See AI agent imports.
Provisioning for Barracuda
Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.
Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
Provisioning for SafetyCulture
Provisioning is now available for the SafteyCulture app integration. See Integrate Safetyculture with Okta.
Provisioning for Toggl
Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.
Provisioning for Moodle
Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.
Provisioning for Elastic Search
Provisioning is now available for the Elastic Search app integration. See Integrate Elastic Search with Okta.
Provisioning for QualtricsXM
Provisioning is now available for the QualtricsXM app integration. See Integrate Qualtrics XM with Okta.
Provisioning for HERE
Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.
Okta Provisioning Agent, version 3.3.0
Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.
Okta Active Directory agent, version 3.23.0
This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.
New Research Release lifecycle
A new Research Release lifecycle, marked with a Research Release banner, is now available for Okta admin documentation. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.
New Proxy service for enhanced dynamic zones
PROXYLINE_PROXY is now supported as an individual Proxy service category in enhanced dynamic zones. See Supported IP categories.
Request subscriptions data export
To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.
New System Log events for Office 365 app-based provisioning
The System Log now logs the following events for app-based authentication for Office 365 provisioning:
- app.office365.provisioning_app.create: This event is logged when Okta creates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning.
- app.office365.provisioning_app_credential.rotate: This event is logged when Okta rotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning. The Outcome field in this event's data indicates whether the client secret rotation was successful or not.
Application-based authentication for Office 365 provisioning
Okta now creates a dedicated app in your Microsoft Entra ID tenant instead of a service account for User Sync and Universal Sync provisioning. This app supports app-based authentication and helps improve your org's security. If you have existing User Sync or Universal Sync configurations, you must reauthenticate and consent to two new permissions by September 30, 2026. See Provide Microsoft admin consent for Okta.
Update group rule assignments
Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.
Import unlicensed users from Azure Active Directory to Okta
You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.
On-demand rotation of Office 365 SSO signing certificates
Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.
Original source All of your release notes in one feed
Join Releasebot and get updates from Okta and hundreds of other software products.
- August 2026
- No date parsed from source.
- First seen by Releasebot:Aug 13, 2026
Okta Classic Engine 2026.08.0
Okta Classic Engine adds broad provisioning support for Barracuda WAF-as-a-Service, Linear, Appspace, SafetyCulture, Toggl, Moodle, Elastic Search, QualtricsXM, and HERE, plus updates to the Provisioning Agent and Active Directory agent with security, import, and entitlement improvements.
Version: 2026.08.0
Provisioning for Barracuda
Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.
Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
Provisioning for SafetyCulture
Provisioning is now available for the SafteyCulture app integration. See Integrate Safetyculture with Okta.
Provisioning for Toggl
Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.
Provisioning for Moodle
Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.
Provisioning for Elastic Search
Provisioning is now available for the Elastic Search app integration. See Integrate Elastic Search with Okta.
Provisioning for QualtricsXM
Provisioning is now available for the QualtricsXM app integration. See Integrate Qualtrics XM with Okta.
Provisioning for HERE
Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.
Okta Provisioning Agent, version 3.3.0
Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.
Okta Active Directory agent, version 3.23.0
This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.
Request subscriptions data export
To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.
Original source - Aug 3, 2026
- Date parsed from source:Aug 3, 2026
- First seen by Releasebot:Aug 7, 2026
2026.07.3
Okta Classic Engine fixes provisioning, Sign-In Widget, admin console, reporting, and governance issues while improving reliability for large orgs. It also adds updates and new availability across the Okta Integration Network.
Fixes
- When an admin modified a LinkedObject attribute value on a user profile, Okta failed to push the updated value to downstream provisioning-enabled apps. (OKTA-311345)
- When admins configured the app setting When a user is deactivated in the app to Do nothing alongside a Post-Termination Interval, user imports from SuccessFactors failed to unassign terminated users. (OKTA-1115401)
- When users clicked the privacy policy link in the Sign-in Widget, they were redirected to the sign-in page instead of the privacy policy page. (OKTA-1201388)
- Some admins saw 500 errors when they tried to delete authorization servers in bulk. (OKTA-1208896)
- In some orgs, when admins created an OIDC web app, the client credentials grant type didn't appear, even though the correct feature flags were enabled. (OKTA-1221984)
- The Okta password health report timed out for orgs with large user directories and returned incomplete data. Reports for large orgs are now limited to a maximum of 500,000 users to ensure reliable performance. (OKTA-1151306)
- The Identity Governance pages had several spelling and punctuation errors. (OKTA-1163458)
- When admins ran an individual realm assignment job, the evaluation process stopped after encountering a single user evaluation failure. (OKTA-1193971)
- On the Welcome and Create Account activation pages on mobile devices, the brand logo was misaligned. (OKTA-1203670)
- In the Admin Console, when admins configured protected actions, the UI displayed both Reset factors for super admins and Reset authenticators for super admins simultaneously. (OKTA-1205255)
- When admins enabled user provisioning features in SCIM 1.0 using On-Premises Provisioning, the schema discovery flow broke. (OKTA-1210290)
- Admins could create a custom token claim named ver for an OpenID Connect app, even though ver is a reserved claim in the ID token. (OKTA-1222755)
- Some proxies and VPNs weren't supported as IP service categories in enhanced dynamic zones. (OKTA-1223345)
Okta Integration Network
- Airbyte Lifecycle Management Connector by Redblock (SCIM) was updated with a new app name and description.
- Cisco User Management Connector (SAML) is now available. Learn more.
- Clarion by Cantina (API Service) has the okta.groups.manage scope.
- DeleteMe (SCIM) has updated endpoints. Learn more.
- Emergent (SAML) is now available. Learn more.
- GreyMatter Transit (API Service) is now available. Learn more.
- Spark HR (OIDC) is now available. Learn more.
- Spark HR (SCIM) is now available. Learn more.
- SpotDraft (SCIM) was updated. Learn more.
- Jul 21, 2026
- Date parsed from source:Jul 21, 2026
- First seen by Releasebot:Aug 7, 2026
2026.07.2
Okta Classic Engine releases general availability fixes for Profile Editor, provisioning, admin UI, reports, realms, and mobile branding, while also expanding the Okta Integration Network with new app integrations and updates for Bitwarden, Cribl Cloud, SparkToro, Toggl, and more.
Generally Available
Fixes
- In Profile Editor, when an admin clicked the info icon next to the Licenses attribute for the Google app, the Attribute members list became editable instead of read-only. (OKTA-182607)
- In the Secure Partner Access Admin Portal, profile attributes from external IdPs incorrectly appeared as editable fields. (OKTA-1124860)
- When an admin permanently deleted a deactivated user, downstream apps provisioned using SCIM didn't receive a deprovisioning request if the user inherited the app assignment through an Okta-managed group. (OKTA-1186388)
- When an on-premises provisioning operation failed, the resulting error message displayed an inaccurate error code. (OKTA-1199729)
- When admins attempted to reassign a user to a custom app that used on-premises provisioning, the reactivation request failed. (OKTA-1210786)
- In some orgs, when admins created an OIDC web app, the client credentials grant type didn't appear, even though the correct feature flags were enabled. (OKTA-1221984)
- The Okta password health report timed out for orgs with large user directories and returned incomplete data. Reports for large orgs are now limited to a maximum of 500,000 users to ensure reliable performance. (OKTA-1151306)
- The Identity Governance pages had several spelling and punctuation errors. (OKTA-1163458)
- When admins ran an individual realm assignment job, the evaluation process stopped after encountering a single user evaluation failure. (OKTA-1193971)
- On the Welcome and Create Account activation pages on mobile devices, the brand logo was misaligned. (OKTA-1203670)
- In the Admin Console, when admins configured protected actions, the UI displayed both Reset factors for super admins and Reset authenticators for super admins simultaneously. (OKTA-1205255)
- When admins enabled user provisioning features in SCIM 1.0 using On-Premises Provisioning, the schema discovery flow broke. (OKTA-1210290)
- Admins could create a custom token claim named ver for an OpenID Connect app, even though ver is a reserved claim in the ID token. (OKTA-1222755)
- Some proxies and VPNs weren't supported as IP service categories in enhanced dynamic zones. (OKTA-1223345)
Okta Integration Network
- Airbyte by Redblock (SCIM) is now available. Learn more.
- Bitwarden (OIDC) is now available. Learn more.
- Bitwarden (SAML) is now available. Learn more.
- Cribl Cloud (SAML) is now available. Learn more.
- KnowledgeOwl Author Provisioning (SCIM) is now available. Learn more.
- Levenza (SAML) has a new app name, description, icon, and integration guide.
- Lolipop! Static IP Access (SCIM) is now available. Learn more.
- Rapid7 InsightAppSec (SAML) has a new app name.
- SafetyCulture (SAML) is now available. Learn more.
- SparkToro (OIDC) is now available. Learn more.
- SparkToro (SCIM) is now available. Learn more.
- Toggl (SAML) is now available. Learn more.
Similar to Okta Classic Engine with recent updates:
- Claude Code updates437 release notes · Latest Sep 5, 2026
- Claude updates136 release notes · Latest Sep 2, 2026
- Claude Developer Platform updates157 release notes · Latest Sep 3, 2026
- Google Workspace updates58 release notes · Latest Sep 4, 2026
- Microsoft 365 updates70 release notes · Latest Sep 1, 2026
- ChatGPT updates216 release notes · Latest Sep 3, 2026
- Jul 21, 2026
- Date parsed from source:Jul 21, 2026
- First seen by Releasebot:Jul 31, 2026
2026.07.2
Okta Classic Engine starts deploying Update 2 on July 21.
2026.07.2: Update 2 started deployment on July 21
Original source - Jul 13, 2026
- Date parsed from source:Jul 13, 2026
- First seen by Releasebot:Aug 7, 2026
2026.07.1
Okta Classic Engine adds generally available provisioning for Linear and Appspace, expanding app setup and security options. It also improves language handling and admin behavior, fixes LDAP Agent version display and import safeguard alerts, and updates several Okta Integration Network apps.
Generally Available
Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
Fixes
- When the display language was set to Japanese, the people/groups counts on the People and Groups pages weren't translated. (OKTA-926579)
- In Profile Editor, super admins could set a custom user type as default by modifying the isDefault field in the network payload. (OKTA-991083)
- During installation, the LDAP Agent (version 5.26.0) incorrectly displayed its version number as the latest Active Directory Agent version (3.22.0). (OKTA-1166327)
- When an Active Directory import safeguard was triggered, Okta incorrectly sent email alerts to users who were no longer admins. (OKTA-1208675)
Okta Integration Network
- AppLovin (SWA) was updated.
- CallPlease has two new ACS URLs and a new configuration guide. Learn more.
- Glean (OIDC) is now available. Learn more.
- Stack Internal (SAML) was updated. Learn more.
- Willow (OIDC) is now available. Learn More.
- Jul 13, 2026
- Date parsed from source:Jul 13, 2026
- First seen by Releasebot:Jul 14, 2026
Okta Classic Engine 2026.07.1
Okta Classic Engine adds provisioning for Linear and Appspace, including security features like Entitlement Management.
2026.07.1: Update 1 started deployment on July 13
Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
Original source - Jul 1, 2026
- Date parsed from source:Jul 1, 2026
- First seen by Releasebot:Jul 7, 2026
- Modified by Releasebot:Aug 7, 2026
2026.07.0
Okta Classic Engine releases July 2026 updates for provisioning, app integrations, and admin workflows, including Rapid7 InsightAppSec and SAP BTP provisioning, Office 365 and Azure AD import improvements, group push and DirSync enhancements, and UI changes that streamline Access Requests and certificate rotation.
Version: 2026.07.0
July 2026
Generally Available
Provisioning for Rapid7 InsightAppSec
Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.
Reassign steps to multiple users
You can now reassign steps within an approval sequence or request type to 10 users. This applies to tasks, questions, actions, and approvals.
Provisioning for SAP BTP
Provisioning is now available for the SAP BTP app integration. When you provision the app, you can enable security features like Entitlement Management.
Admin OIDC App Phase Two Tranch One
When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.
UI updates to Okta Access Requests web app
The All requests page in the Okta Access Requests web app now shows 999+ count if there are 1000 or more requests instead of giving the count. This change helps reduce the time taken to list the requests on the page.
Import Azure Active Directory users with null first and last name
You can now import users from Microsoft Azure Active Directory (AAD) who have null first name and last name values. This provides admins with a centralized view of their AAD users within Okta. See Import users to Office 365 using Microsoft Graph API.
Removal of search filters from the Inbox page
The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.
New VPN service for enhanced dynamic zones
The VIGOR_SSL_VPN is now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
Improved MFA enrollment policy validator
Orgs that have no self-initiated user.account.update_password syslog events over last 30 days are now excluded from the MFA enrollment policy validator warning triggered during the Okta Identity Engine upgrade, making it easier to upgrade.
Import unlicensed users from Azure Active Directory to Okta
You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.
Role-assignable push groups for Office 365
When you create a new push group for the Office 365 app integration, select the Is this role assignable checkbox to make the group role assignable in Microsoft Entra ID. This allows you to push Okta groups to Microsoft Entra ID and assign roles instead of manually creating groups in Entra ID and then linking them to Okta using push groups. See Configure Push Group.
Group push support in API Integration Actions apps
Apps that use API Integration Actions to perform provisioning can now use the Group Push feature. This enables the group import functionality for apps that use group API contracts in their provisioning actions.
DirSync group imports for Active Directory
For Active Directory (AD) integrations, the Provisioning tab now provides an Enable imports with AD using DirSync checkbox. When you enable the checkbox, admins can perform incremental group imports using DirSync. See Configure Active Directory import and account settings.
On-demand rotation of Office 365 SSO signing certificates
Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.
Original source - May 2026
- No date parsed from source.
- First seen by Releasebot:May 12, 2026
- Modified by Releasebot:May 23, 2026
Okta Classic Engine release notes (Production)
Okta adds Workday entitlement management, richer access request condition descriptions, new CSV and GZIP report exports, and expanded System Log and network zone visibility, while also shipping several fixes and new or updated Okta Integration Network apps.
Version: 2026.05.0
Workday entitlement management
Admins can now manage entitlements for Workday app instances on Okta. This feature allows for the discovery and governance of user-based security groups to enable automated access requests and certifications.
Report exports
You can now choose between CSV and GZIP export formats when generating the following reports:
- Okta usage
- Application usage
- MFA usage
Add access request condition descriptions
You can now add descriptions to access request conditions for apps, collections, and Okta admin role bundles. These descriptions appear alongside the condition's name on the Access Requests tab, making it easier for you to understand the specific purpose of each condition. See Create access request conditions.
System Log event for unconfigured identifiers
When JIT is enabled for Active Directory and a user authenticates with an unconfigured identifier, the event now appears in the System Log.
System Log event for DirSync imports
When Active Directory agent compatibility is verified for DirSync-based imports, the event now appears in the System Log.
Network zone residential proxy detection
This feature adds new zones associated with Enhanced Dynamic Network Zones beyond anonymous proxies and VPNs. Customers can use service categories such as ZSCALER_PROXY, PERIMETER_81, and more. See Supported IP service categories.
Fixes
- After deactivating an AD Agent, an incorrect format of the version for the agent was displayed. (OKTA-1117122)
- The Sign-In Widget displayed an error after users completed a self-service password reset when the app authentication policy had the Keep Me Signed In prompt enabled. (OKTA-1152243)
- AMR claim updates weren't applied to the Salesforce (Federated ID) app integration. (OKTA-1164030)
- On the Administrator assignment by role page, the Preview role pane displayed "L10N_ERROR[okta.apps.clientCredentials.read.name.code]" instead of the View client credentials permission. (OKTA-1166616)
- Manual remediation was required when reviewers revoked a user’s access to Active Directory-source groups in a campaign. (OKTA-1167090)
Okta Integration Network
- TOPdesk Operator by FuseLogic (SCIM) was updated.
- Magnite Streamr (OIDC) is now available. Learn more.
- Matik (Basic Auth) was updated.
- Console (OIDC) has a new app description.
- Sastrufy has a new app name and a new configuration guide.
- WideField Security - Detect and Remediate (API integration) is now available. Learn more.
- Console (API Service) has a new icon and description.
- Yunu (OIDC) is now available. Learn more.
- YipitData Agent (OIDC) is now available. Learn more.
- Software Analytics (OIDC) has a new app name (Antenna), icon, description, new Redirect URIs, and integration guide. Learn more.
- Ternary (OIDC) is now available. Learn more.
- Syndio (OIDC) is now available. Learn more.
- Form (OIDC) is now available. Learn more.
- Truepic Vision (OIDC) is now available. Learn more.
- Tandem Health (OIDC) is now available. Learn more.
- CJ Affiliate (OIDC) is now available. Learn more.
- Asset Integrity for Pipelines (OIDC) is now available. Learn more.
- Metlife MyBenefits (SWA) was updated.
- Conduit Security (OIDC) is now available. Learn more.
- Harmony (SCIM) is now available. Learn more.
- Harmony (SAML) is now available. Learn more.
- LinkedIn Sales Navigator (SCIM) is now available. Learn more.
- Haystack (SCIM) is now available. Learn more.
- Suger (OIDC) has a new Redirect URI.
- ThoughtSpot (OIDC) is now available. See Create ThoughtSpot OIDC integration.
- Matik (SCIM) is now available. Learn more.
- Matik (SAML) is now available. Learn more.
- JumpCloud (OIDC) is now available. See JumpCloud.
- TOPdesk Operator by FuseLogic (Entitlements Management) is now available. Learn more.
- Apr 1, 2026
- Date parsed from source:Apr 1, 2026
- First seen by Releasebot:Apr 7, 2026
- Modified by Releasebot:May 9, 2026
Okta Classic Engine release notes (Production)
Okta adds Slack integration for Identity Governance, custom admin permissions for inline and event hooks, expanded access duration limits, new System Log security fields, MuleSoft Anypoint Platform provisioning, and IBM Db2 LUW support, plus fixes and Okta Integration Network updates.
Version: 2026.04.0
April 2026
Generally Available
Slack integration for Identity Governance
Okta for Government Moderate and Government High customers who use commercial Slack instances can now integrate Slack with their org to streamline access management in Access Requests and Access Certifications. Users can now submit and approve requests in Slack as well as receive Slack notifications for access requests and certification campaigns. Feature availability varies depending on whether the Unified requester experience feature is enabled. See Okta Identity Governance Limitations for Public Sector Service and Integrate Slack.
Custom admin permissions for inline and event hooks
The inline hook and event hook framework now supports read and write permissions for custom admin roles. This enhancement gives fine-grained access to manage inline and event hooks that previously required the super admin role. See Role permissions.
Okta Active Directory Federation Services (ADFS) Plugin version 1.8.4
This version includes bug fixes and security updates.
Provisioning for MuleSoft Anypoint Platform
Admins can now automate user lifecycle management for the MuleSoft Anypoint Platform app. This integration supports creating, updating, and deactivating users, and pushing groups as teams. See MuleSoft Anypoint Platform provisioning.
Increase to the maximum access duration limit
When you create or edit access request conditions, you can now set the Access duration field to a maximum of 365 days or 52 weeks.
New System Log objects for security.request.blocked events
The System Log now displays the following IpDetails objects for dynamic and enhanced dynamic zones:
- Operator indicates whether the type is VPN or Proxy
- Type includes values like VPN, Proxy, and Tor
- IsAnonymous indicates if the proxy is anonymous
These objects move risk and behavior telemetry out of string-only keys in the debug context and into dedicated, structured fields in the security context event. This change improves risk visibility and eliminates the need for string parsing.
Early Access
Radius Agent version 2.5
This version includes internal improvements and fixes.
IBM Db2 LUW support for On-premises Connector for Generic Databases
The On-premises Connector for Generic Databases now supports IBM Db2 LUW. This enables admins to manage users and entitlements in IBM Db2 LUW environments. See On-premises Connector for Generic Databases.
Fixes
- Data was missing from the policy.rule.update System Log event. (OKTA-888091)
- Apps created from the On-premises Connector for Generic Databases incorrectly appeared on the End-User Dashboard. Clicking the app resulted in an invalid redirect because the connector doesn't support SSO. (OKTA-1076893)
- An incorrect error message was displayed when a Bidirectional Group Management issue occurred. (OKTA-1104305)
- When an admin used a JDBC on-premises app, provisioning failed with a Requires a successful schema discovery error on the Provisioning tab. (OKTA-1124752)
- When an admin deactivated a Group Push mapping rule, membership updates stopped for previously matched groups. (OKTA-1125151)
- When a DirSync import failed with a permission error, the agent was operational but had the Disruption label in the Admin Console. (OKTA-1128087)
Okta Integration Network
- Dokio now supports an additional custom attribute.
- Reftab Discovery (API Service) now supports the Groups Read scope.
- ZoomInfo (SCIM) was updated.
- Mar 16, 2026
- Date parsed from source:Mar 16, 2026
- First seen by Releasebot:Mar 10, 2026
- Modified by Releasebot:Mar 18, 2026
March 2026
Okta releases 2026.03.0 GA with better error handling for group searches, admin console spotlight results, and flexible Office 365 provisioning. It rebrands Yammer to Microsoft Viva, adds enhanced disaster recovery options, DirSync import optimizations, and new integrations, plus several fixes.
Version: 2026.03.0
March 2026
Generally Available
Improved error handling for group membership searches
When an internal error is returned for a group membership search, the ordering and sorting direction options are removed and the search is performed again.Admin Console recent search results
The spotlight search now displays the admin's recent search results. See Admin Console search.Yammer rebranded to Microsoft Viva
The Yammer integration in Microsoft Office 365 now displays the Microsoft Viva logo and directs users to the Microsoft Viva homepage. This update supports Viva Insights and Viva Connections in GCC environments.Enhanced provisioning controls for Microsoft Office 365
Admins can now configure the Microsoft Office 365 integration to sync only user profile attributes, or to sync attributes, licenses, and roles. This setting helps prevent Okta from overwriting licenses and roles that are managed directly in Microsoft. See Provision users to Office 365.Early Access
Improved DirSync-based imports
Optimize performance of AD DirSync-based imports by skipping unnecessary prechecks and downloading organizational units without using DirSync.Self-Service for Enhanced Disaster Recovery
When unexpected infrastructure-related outages occur, orgs need an immediate and reliable way to maintain business continuity. Okta's Standard Disaster Recovery, implemented by Okta's operations teams, provides failover and failback with a recovery time objective of one hour.Okta's Enhanced Disaster Recovery (Enhanced DR) gives admins the option to manage their org's recovery. This feature empowers admins by providing direct, self-service tools and APIs to manage, test, and automate the failover and restoration processes for their impacted orgs.
With Enhanced DR, admins gain active control to initiate a failover and restore for impacted orgs directly from the Okta Disaster Recovery Admin portal or through APIs. Additionally, teams can validate their system's resilience by safely testing these failover and restoration capabilities at their convenience. Finally, Enhanced DR enables orgs to automate failover processes by using real-time monitoring to invoke failover APIs, significantly minimizing downtime during an actual event. See Okta disaster recovery.
Fixes
You couldn't search for and select users with Provisioned, Active, Recovery, Password Expired, or Locked out status when assigning a step in an approval sequence and in request types. (OKTA-944822)
Group rules sometimes behaved unpredictably when multiple distinct transactions ran the rules on the same user at the same time. (OKTA-954076)
When AD-sourced users attempted to sign in using an expired temporary password and self-service password change was disabled, an incorrect error message was displayed. (OKTA-1113434)
Okta Integration Network
Guardare (SAML) is now available. Learn more.
Valence Remediation (API) is now available. Learn more.
Cato Networks Provisioning now supports user imports and updates.
PerimeterX now supports SAML.
PerimeterX now supports SCIM.
Druva Data Security Cloud (API Service) now has the okta.clients.read scope.
Natoma has a new app icon.
Adobe Creative (SWA) was updated.
Adobe Fonts (SWA) was updated.
Weekly Updates
2026.03.1: Update 1 started deployment on March 16
Generally Available
Fixes
An error occurred when an admin attempted to add a duplicate SWA integration. (OKTA-600590)
When DirSync was enabled, AD incremental imports removed group description values in Okta. (OKTA-1108167)
When an admin integrated an app through the API, some of the custom SSO properties didn't populate on the integration page. (OKTA-1109692)
The Add Resource dialog couldn't load more users or groups if the search term included special characters. (OKTA-1114749)
When an admin pressed the Enter key to select a recent spotlight search result, the search field disappeared. (OKTA-1115374)
The Microsoft Teams app integration incorrectly redirected users to an outdated URL during the Secure Web Authentication (SWA) flow. (OKTA-1117744)
Workflows admins couldn't edit their admin email notifications. (OKTA-1119296)
When admins provisioned users, incremental synchronizations for permission sets failed. The connector pushed duplicate permission set assignments, which resulted in errors for sets already assigned to the user. (OKTA-1121168)
Admins could initiate temporary password resets for users sourced from Okta, Active Directory (AD), or LDAP, bypassing the password policy that disabled self-service password reset. (OKTA-1122913)
Okta Integration Network
CyberProof Threat Exposure Management Platform (API integration) is now available. Learn more.
Google Cloud Workforce Identity Federation (SAML) is now available. Learn more.
Google Cloud Workforce Identity Federation (SCIM) is now available. Learn more.
Sensor Tower (SAML) is now available. Learn more.
YakChat (OIDC) is now available. Learn more.
Google Cloud Workforce Identity Federation (OIDC) has a new Redirect URI. Learn more.
JetBrains (SWA) was updated.
- Mar 1, 2026
- Date parsed from source:Mar 1, 2026
- First seen by Releasebot:Sep 17, 2025
- Modified by Releasebot:Apr 5, 2026
March 2026
Okta releases 2026.03.0 with improved group membership search recovery, Admin Console recent search results, and stronger Office 365 provisioning controls. It also adds Enhanced Disaster Recovery self-service tools, speeds up DirSync imports, and includes multiple fixes and new Okta Integration Network updates.
Version: 2026.03.0
Generally Available
Improved error handling for group membership searches
When an internal error is returned for a group membership search, the ordering and sorting direction options are removed and the search is performed again.
Admin Console recent search results
The spotlight search now displays the admin's recent search results. See Admin Console search.
Yammer rebranded to Microsoft Viva
The Yammer integration in Microsoft Office 365 now displays the Microsoft Viva logo and directs users to the Microsoft Viva homepage. This update supports Viva Insights and Viva Connections in GCC environments.
Enhanced provisioning controls for Microsoft Office 365
Admins can now configure the Microsoft Office 365 integration to sync only user profile attributes, or to sync attributes, licenses, and roles. This setting helps prevent Okta from overwriting licenses and roles that are managed directly in Microsoft. See Provision users to Office 365.
Early Access
Improved DirSync-based imports
Optimize performance of AD DirSync-based imports by skipping unnecessary prechecks and downloading organizational units without using DirSync.
Self-Service for Enhanced Disaster Recovery
When unexpected infrastructure-related outages occur, orgs need an immediate and reliable way to maintain business continuity. Okta's Standard Disaster Recovery, implemented by Okta's operations teams, provides failover and failback with a recovery time objective of one hour.
Okta's Enhanced Disaster Recovery (Enhanced DR) gives admins the option to manage their org's recovery. This feature empowers admins by providing direct, self-service tools and APIs to manage, test, and automate the failover and restoration processes for their impacted orgs.
With Enhanced DR, admins gain active control to initiate a failover and restore for impacted orgs directly from the Okta Disaster Recovery Admin portal or through APIs. Additionally, teams can validate their system's resilience by safely testing these failover and restoration capabilities at their convenience. Finally, Enhanced DR enables orgs to automate failover processes by using real-time monitoring to invoke failover APIs, significantly minimizing downtime during an actual event. See Okta disaster recovery.
Fixes
- You couldn't search for and select users with Provisioned, Active, Recovery, Password Expired, or Locked out status when assigning a step in an approval sequence and in request types. (OKTA-944822)
- Group rules sometimes behaved unpredictably when multiple distinct transactions ran the rules on the same user at the same time. (OKTA-954076)
- When AD-sourced users attempted to sign in using an expired temporary password and self-service password change was disabled, an incorrect error message was displayed. (OKTA-1113434)
Okta Integration Network
- Guardare (SAML) is now available. Learn more.
- Valence Remediation (API) is now available. Learn more.
- Cato Networks Provisioning now supports user imports and updates.
- PerimeterX now supports SAML.
- PerimeterX now supports SCIM.
- Druva Data Security Cloud (API Service) now has the okta.clients.read scope.
- Natoma has a new app icon.
- Adobe Creative (SWA) was updated.
- Adobe Fonts (SWA) was updated.
- Feb 1, 2026
- Date parsed from source:Feb 1, 2026
- First seen by Releasebot:Oct 14, 2025
- Modified by Releasebot:Feb 28, 2026
Okta Classic Engine release notes (Production)
Okta releases cover Okta Mobile End of Life set for May 31, 2026 with migration options. New and updated features include LDAP bidirectional group management, Zoho Mail group push, and WS-Trust 1.3 support for Windows Transport.
Version: 2026.02.0
February 2026
Generally Available
Okta Mobile End of Life
The Okta Mobile app will transition to End of Life (EOL) status on May 31, 2026.
After this deprecation date, Okta Mobile will not receive any further security updates, bug fixes, or support. The app will no longer be available for download through the Apple App Store or the Google Play Store.
Okta previously announced the End of Support for Okta Mobile, effective November 1, 2025.
See Okta Mobile End of Life for available migration solutions.Group push for Zoho Mail
Group push is now available for the Zoho Mail app integration. See Zoho Mail supported features.
Okta Provisioning agent, version 3.0.7
Okta Provisioning agent 3.0.7 is now available. This release contains the following updates:
- The Generic Database Connector now supports Base64 encoded path parameters.
- Root ownership and permissions for the /var/run directory are restored in the OPP agent RPM build.
Access revoked notifications
For access requests that are managed by conditions, requesters now get notified when their access to a resource expires. Requesters are notified by email, Slack, or Microsoft Teams depending on your configurations.
Admin Console French translation
Now when you set your display language to French, the Admin Console is also translated. See Supported display languages.
Agents page description
The Agents page now provides a helpful description so admins can quickly understand the scope and purpose of the page. See View your org agents' status.
Protected action notifications removed
For orgs that have migrated to OIDC, toast notifications no longer appear when an admin performs a protected action. See Protected actions in the Admin Console. This update is following a slow rollout process.
LDAP Bidirectional Group Management
Bidirectional Group Management for Lightweight Directory Access Protocol (LDAP) allows you to manage LDAP groups from within Okta. You can add or remove users from groups based on their identity and access requirements. This ensures that changes made to user access in Okta are reflected in LDAP.
Okta can only manage group memberships for users and groups imported into Okta using the LDAP or Active Directory (AD) integration. It isn't possible to manage users and groups that weren't imported through LDAP or AD integration or are outside the organizational unit's scope for the integration using this feature.Radius Agent version 2.26
This version includes internal improvements and fixes.
WS-Trust 1.3 support for Windows Transport
Windows Transport now supports WS-Trust 1.3 protocol. This enables Silent Activation for newer Microsoft Office clients, eliminating the need for users to manually enter their credentials.
Original source - December 2025
- No date parsed from source.
- First seen by Releasebot:Dec 17, 2025
- Modified by Releasebot:Jun 23, 2026
Okta Classic Engine release notes (Production)
Okta adds Salesforce provisioning support for PKCE, richer System Log network zone details, SHA-256 support for SAML AuthnRequests, and improved service account, navigation, and request experience updates across the Admin Console.
Version: 2026.06.0
Salesforce provisioning support for PKCE
The Salesforce app integration now supports Proof Key for Code Exchange (PKCE) for OAuth 2.0 flows. This update ensures uninterrupted user provisioning and requires admins to update their Salesforce configuration to maintain service continuity.
Improved network zone error messages
The error message that appears when admins try to delete a network zone that's referenced by multiple policies or rules is now easier to read.
Secure SaaS and Okta Service Accounts
Manage and secure passwords for SaaS app service accounts and Okta service accounts with Okta Privileged Access. You can now assign new Service Accounts permissions to custom roles to delegate service account management duties to non-super admins. See Manage service accounts and Role permissions.
New System Log fields for matched network zones
Okta now includes richer network zone match information in System Log events. When a request is blocked by a network zone (security.request.blocked) or evaluated against a sign-on policy (policy.evaluate_sign_on), the System Log now surfaces the names and IDs of all matched network zones, across IP zones, Dynamic Network Zones (DNZ), and Enhanced Dynamic Network Zones (EDNZ), through new ZoneIdMatch and ZoneNameMatch fields. Up to 10 matched zones are reported per event.
These new fields provide more granular and structured network zone context than the existing Client.Zone field. This gives admins and security teams precise, actionable detail for blocked requests and policy evaluations, making SIEM investigations and audit reviews significantly easier. See Troubleshoot network zone issues using System Log.
SHA-256 digest algorithm support
Okta now supports the SHA-256 digest algorithm when hashing SAML AuthnRequests that are sent to external IdPs.
Navigation label update for integration agents
The Agents label in the Admin Console has been renamed to Integration agents to provide a more intuitive experience. A dismissible link to the AI Agents page is also available on the Integration agents page to improve navigation.
Improved request details layout
The request details page now features an optimized layout for small screens to improve readability.
Seamless ISV experience for SCIM
Okta now provides a seamless ISV experience to optimize the [Okta Integration Network (OIN)] submission experience for SCIM integrations. This new experience enables independent software vendors (ISVs) to build and manually test their SCIM integration metadata before submission to the OIN. This reduces the time needed for the OIN team to review and validate that the SCIM integration functions as intended, which shortens the time to publish in the OIN. This experience also incorporates communication processes in Salesforce, enabling improved collaboration internally within Okta teams and externally with ISVs. See [Publish an OIN integration overview] and [Submit an integration with the OIN Wizard] guide.
Links: 1. https://www.okta.com/integrations/ 2. https://developer.okta.com/docs/guides/submit-app-overview/ 3. https://developer.okta.com/docs/guides/submit-oin-app/scim/main/
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.