Okta Identity Engine Updates & Release Notes
7 updates curated from 2 sources by the Releasebot Team. Last updated: Jul 22, 2026
- Jul 21, 2026
- Date parsed from source:Jul 21, 2026
- First seen by Releasebot:Jul 22, 2026
2026.07.2
Okta Identity Engine ships Sign-In Widget 7.47.1 with an agent-to-agent audience update that allows a free-form server resource URL, plus a new Device Visibility experience for macOS and Windows that puts key user, enrollment, and security signals in one four-tab view.
Sign-In Widget, version 7.47.1
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Agent-to-agent audience update
The agent-to-agent server resource url (audience parameter) can now be a free-form string.
Device Visibility feature for macOS and Windows
Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.
Original source - Jul 13, 2026
- Date parsed from source:Jul 13, 2026
- First seen by Releasebot:Jul 15, 2026
- Modified by Releasebot:Jul 16, 2026
2026.07.1
Okta Identity Engine adds AI agent imports from Microsoft 365, new Anthropic (Claude) SAML SSO, and provisioning updates for Linear and Appspace, plus expanded Android device assurance support.
Import AI agents from Microsoft Office 365
You can now import and manage AI agents built in Microsoft Copilot Studio and Microsoft AI Foundry directly through Okta. See AI agent imports.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Anthropic (Claude) SAML SSO integration
A new SAML 2.0 SSO integration for Anthropic (Claude) is now in the Okta Integration Network. This integration includes the existing Anthropic AI Agent. This feature is available to customers who have Okta for AI Agents. See Integrate Claude with Okta.
Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
Original source All of your release notes in one feed
Join Releasebot and get updates from Okta and hundreds of other software products.
- Jul 7, 2026
- Date parsed from source:Jul 7, 2026
- First seen by Releasebot:Jul 7, 2026
2026.07.0
Okta Identity Engine adds broader AI agent management, device assurance, and access request updates, with new support for AI agent imports, roles, event hooks, and secure token exchange. It also expands provisioning, group and certificate controls, plus new OS support and threat protection improvements.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Spec-compliant client ID claims for AI agent tokens
Okta Expression Language profiles now include the app.clientId property during user claim evaluations for AI agent OAuth 2.0 clients. This allows developers to generate spec-compliant tokens during AI agent flows.
OAuth secure token exchange for Salesforce requests
Okta for AI Agents now uses the OAuth 2.0 secure token exchange flow when it sends requests to the Salesforce app integration, resource server, or MCP server.
AI agent events are now event-hook eligible
The AI agent and AI agent provider events are now event-hook eligible, enabling Workflows to be triggered based on events. See Event hooks.
Provisioning for Rapid7 InsightAppSec
Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.
Reassign steps to multiple users
You can now reassign steps within an approval sequence or request type to 10 users. This applies to tasks, questions, actions, and approvals.
Admin OIDC App Phase Two Tranch One
When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.
Sign-In Widget, version 7.46.2
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Unique client authorization settings required for OIN apps
When you enter client authorization details for an app integration, an error now appears if another integration already uses those details.
New protocol runtime for Amazon Bedrock AgentCore AI agents
You can now import both standard HTTP and agent-to-agent protocol runtimes from the Amazon Bedrock AgentCore platform.
MCP servers active by default
Newly created MCP servers are now in an active state by default. See Add MCP servers.
AI agent admin role
Super admins can now delegate AI agent management tasks using the new AI agent admin role. Admins with this role can perform tasks like registering AI agents, assigning owners, and configuring resource connections. See Manage Okta for AI Agents admin roles.
Date range filter for AI agents
The AI Agents page now provides a date range filter so admins can filter AI agents by when they were created or updated.
Import AI agents from Google Vertex AI
You can now import and manage AI agents built in Google Vertex AI directly through Okta. See Configure Google Vertex AI for AI agent imports.
Sign-In Widget, version 7.46.3
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 17 (2026-06-01)
- Windows 10 builds (10.0.17763.8880, 10.0.19044.7417, 10.0.19045.7417)
- Windows 11 builds (10.0.22631.7219, 10.0.26100.8655, 10.0.26200.8655)
UI updates to Okta Access Requests web app
The All requests page in the Okta Access Requests web app now shows 999+ count if there are 1000 or more requests instead of giving the count. This change helps reduce the time taken to list the requests on the page.
Import Azure Active Directory users with null first and last name
You can now import users from Microsoft Azure Active Directory (AAD) who have null first name and last name values. This provides admins with a centralized view of their AAD users within Okta. See Import users to Office 365 using Microsoft Graph API.
Removal of search filters from the Inbox page
The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.
Okta for AI Agents UI updates
The AI agents page now provides Owner and Platform filters. Also, the AI agent providers page now has Registered AI agents column that displays the number of AI agents that are registered from the provider.
Suspicious Login Using A Sprayed Password
This detection indicates that a user's password has been identified in a password spray campaign and used to successfullly sign in. The detection enables ITP to trigger configured remediation actions such as Universal Logout or password reset through a workflow. See Suspicious login using a sprayed password.
This feature is following a slow rollout process.
Bot protection
Bot protection enables orgs to automatically identify and mitigate bot traffic by configuring remediation actions within the Identity Threat Protection (ITP) landing page. See Bot protection.
New VPN service for enhanced dynamic zones
The VIGOR_SSL_VPN is now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
AI agents admin role help link
On the Administrators Roles tab, the AI agents admin role now has a help link.
Maximum number of IDPs in an IDP routing rule increased
The maximum number of allowed IdPs in an IdP routing rule has been increased to 100. See Configure identity provider routing rules.
Advanced posture checks for device assurance
Advanced posture checks let admins configure specific device security conditions beyond what standard device assurance policies support. Using osquery, you can write custom SQL queries to assess device state on macOS and Windows devices, configure checks for unmanaged devices, and integrate with endpoint detection and response (EDR) tools. See Configure advanced posture checks for device assurance.
Okta SSF Transmitter now available to CIAM orgs
Okta uses CAEP to send security-related events and other data-subject signals to third-party security vendors. See Shared Signals Framework.
This feature is now available to Customer Identity and Access Management orgs.
Improved MFA enrollment policy validator
Orgs that have no self-initiated user.account.update_password syslog events over last 30 days are now excluded from the MFA enrollment policy validator warning triggered during the Okta Identity Engine upgrade, making it easier to upgrade.
Clear Managed Chrome Profile Browsing Data
Clear Managed Chrome Profile Browsing Data provides real-time remediation by instantly purging local session data (cookies and cache) within managed Chrome profiles upon ITP detection. By transforming the browser into a policy-enforced workspace, it ensures immediate, automated protection. See Clear managed Chrome profile browsing data.
Import unlicensed users from Azure Active Directory to Okta
You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.
Role-assignable push groups for Office 365
When you create a new push group for the Office 365 app integration, select the Is this role assignable checkbox to make the group role assignable in Microsoft Entra ID. This allows you to push Okta groups to Microsoft Entra ID and assign roles instead of manually creating groups in Entra ID and then linking them to Okta using push groups. See Configure Push Group.
Group push support in API Integration Actions apps
Apps that use API Integration Actions to perform provisioning can now use the Group Push feature. This enables the group import functionality for apps that use group API contracts in their provisioning actions.
Native to Web SSO
Native to Web SSO creates a seamless, unified authentication experience when a user transitions from an OIDC app (like a native or web app) to a web app (either OIDC or SAML). This feature uses standard, web-based federation protocols like SAML and OpenID Connect that help bridge the gap between two different application environments, using a single-use, one-way interclient trust SSO token. This eliminates repeating already provided sign-on assurances, and simplifies development by reducing authentication complexity. See Configure Native to Web SSO.
DirSync group imports for Active Directory
For Active Directory (AD) integrations, the Provisioning tab now provides an Enable imports with AD using DirSync checkbox. When you enable the checkbox, admins can perform incremental group imports using DirSync. See Configure Active Directory import and account settings.
ITP detections for AMFA orgs
Adaptive MFA orgs now benefit from ITP detections on sessions and entity users when these are detected on directly assigned super admins. These detection events are actionable using Workflows. This feature aligns with the Okta Secure Identity Commitment. See Identity Threat Protection events in System Log.
This feature is now available to Okta for US Military customers.
On-demand rotation of Office 365 SSO signing certificates
Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.
Update group rule assignments
Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.
Original source - July 2026
- No date parsed from source.
- First seen by Releasebot:Jul 6, 2026
Version: 2026.07.0
Okta Identity Engine adds AI agent, device assurance, and admin experience updates, including new AI agent roles and imports, stronger token and certificate controls, expanded OS support, advanced posture checks, improved MFA and group rule management, and user and email settings enhancements.
Version: 2026.07.0
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Spec-compliant client ID claims for AI agent tokens
Okta Expression Language profiles now include the app.clientId property during user claim evaluations for AI agent OAuth 2.0 clients. This allows developers to generate spec-compliant tokens during AI agent flows.
OAuth secure token exchange for Salesforce requests
Okta for AI Agents now uses the OAuth 2.0 secure token exchange flow when it sends requests to the Salesforce app integration, resource server, or MCP server.
AI agent events are now event-hook eligible
The AI agent and AI agent provider events are now event-hook eligible, enabling Workflows to be triggered based on events. See Event hooks.
Provisioning for Rapid7 InsightAppSec
Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.
Admin OIDC App Phase Two Tranch One
When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.
Unique client authorization settings required for OIN apps
When you enter client authorization details for an app integration, an error now appears if another integration already uses those details.
New protocol runtime for Amazon Bedrock AgentCore AI agents
You can now import both standard HTTP and agent-to-agent protocol runtimes from the Amazon Bedrock AgentCore platform.
MCP servers active by default
Newly created MCP servers are now in an active state by default. See Add MCP servers.
AI agent admin role
Super admins can now delegate AI agent management tasks using the new AI agent admin role. Admins with this role can perform tasks like registering AI agents, assigning owners, and configuring resource connections. See Manage Okta for AI Agents admin roles.
Date range filter for AI agents
The AI Agents page now provides a date range filter so admins can filter AI agents by when they were created or updated.
Import AI agents from Google Vertex AI
You can now import and manage AI agents built in Google Vertex AI directly through Okta. See Configure Google Vertex AI for AI agent imports.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 17 (2026-06-01)
- Windows 10 builds (10.0.17763.8880, 10.0.19044.7417, 10.0.19045.7417)
- Windows 11 builds (10.0.22631.7219, 10.0.26100.8655, 10.0.26200.8655)
Removal of search filters from the Inbox page
The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.
Okta for AI Agents UI updates
The AI agents page now provides Owner and Platform filters. Also, the AI agent providers page now has Registered AI agents column that displays the number of AI agents that are registered from the provider.
Suspicious Login Using A Sprayed Password
This detection indicates that a user's password has been identified in a password spray campaign and used to successfullly sign in. The detection enables ITP to trigger configured remediation actions such as Universal Logout or password reset through a workflow. See Suspicious login using a sprayed password. This feature is following a slow rollout process.
New VPN service for enhanced dynamic zones
The VIGOR_SSL_VPN is now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
AI agents admin role help link
On the Administrators Roles tab, the AI agents admin role now has a help link.
Strong cipher enforcement for X.509 client certificate authentication
Okta now enforces strong cryptographic ciphers for X.509 client certificates used in mTLS authentication. Client certificates signed with weak ciphers, such as RSA-1024, are no longer accepted for new orgs. If you use X.509 certificate-based authentication, ensure that your client certificates meet FIPS 140-2 cipher requirements.
Customizable emails for Passkeys (FIDO2 WebAuthn) authenticator
The email that users receive when the admin configures a Passkeys (FIDO2 WebAuthn) authenticator is now available as a customizable template in Customizations Brands Emails. Admins can modify the subject line, email body, and dynamic variables such as the PIN, first name, and org name, and can add content in multiple languages.
Email auto-enrollment and recovery management
Admins can control the automatic enrollment of email as an authenticator and configure email-based password recovery, unlock, and change where email is not an authenticator. See Make email an optional authenticator.
Advanced posture checks for device assurance
Advanced posture checks let admins configure specific device security conditions beyond what standard device assurance policies support. Using osquery, you can write custom SQL queries to assess device state on macOS and Windows devices, configure checks for unmanaged devices, and integrate with endpoint detection and response (EDR) tools. See Configure advanced posture checks for device assurance.
Update group rule assignments
Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.
Improved MFA enrollment policy validator
Orgs that have no self-initiated user.account.update_password syslog events over last 30 days are now excluded from the MFA enrollment policy validator warning triggered during the Okta Identity Engine upgrade, making it easier to upgrade.
Import unlicensed users from Azure Active Directory to Okta
You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.
Group push support in API Integration Actions apps
Apps that use API Integration Actions to perform provisioning can now use the Group Push feature. This enables the group import functionality for apps that use group API contracts in their provisioning actions.
ITP detections for AMFA orgs
Adaptive MFA orgs now benefit from ITP detections on sessions and entity users when these are detected on directly assigned super admins. These detection events are actionable using Workflows. This feature aligns with the Okta Secure Identity Commitment. See Identity Threat Protection events in System Log. This feature is now available to Okta for US Military customers.
On-demand rotation of Office 365 SSO signing certificates
Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.
Direct End-User Settings access
Users may now access their Settings page through a direct URL in addition to the End-User Dashboard. This feature provides convenience and security for users, gives admins greater flexibility when working with End-User Dashboard access control scenarios, and includes accessibility and UX improvements. See End-User Settings.
Original source - Jun 29, 2026
- Date parsed from source:Jun 29, 2026
- First seen by Releasebot:Jul 6, 2026
2026.06.3
Okta Identity Engine adds support for importing and managing AI agents built in Google Vertex AI, updates the Sign-In Widget to version 7.46.3, and expands device assurance OS support with new Android and Windows build coverage.
Import AI agents from Google Vertex AI
You can now import and manage AI agents built in Google Vertex AI directly through Okta. See Configure Google Vertex AI for AI agent imports.
Sign-In Widget, version 7.46.3
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 17 (2026-06-01)
- Windows 10 builds (10.0.17763.8880, 10.0.19044.7417, 10.0.19045.7417)
- Windows 11 builds (10.0.22631.7219, 10.0.26100.8655, 10.0.26200.8655)
Similar to Okta Identity Engine with recent updates:
- Google Workspace updates51 release notes · Latest Jul 17, 2026
- Claude Code updates403 release notes · Latest Jul 22, 2026
- Gemini updates356 release notes · Latest Jul 21, 2026
- Claude updates116 release notes · Latest Jul 14, 2026
- Confluence updates135 release notes · Latest May 12, 2026
- Slack For Mac updates25 release notes · Latest May 26, 2026
- Jun 23, 2026
- Date parsed from source:Jun 23, 2026
- First seen by Releasebot:Jul 6, 2026
2026.06.2
Okta Identity Engine adds step reassignment for up to 10 users, new admin OIDC sign-in behavior, stricter OIN app client authorization checks, Bedrock AgentCore runtime imports, default-active MCP servers, and a date range filter for AI agents.
Reassign steps to multiple users
You can now reassign steps within an approval sequence or request type to 10 users. This applies to tasks, questions, actions, and approvals.
Admin OIDC App Phase Two Tranch One
When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.
Sign-In Widget, version 7.46.2
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Unique client authorization settings required for OIN apps
When you enter client authorization details for an app integration, an error now appears if another integration already uses those details.
New protocol runtime for Amazon Bedrock AgentCore AI agents
You can now import both standard HTTP and agent-to-agent protocol runtimes from the Amazon Bedrock AgentCore platform.
MCP servers active by default
Newly created MCP servers are now in an active state by default. See Add MCP servers.
Date range filter for AI agents
The AI Agents page now provides a date range filter so admins can filter AI agents by when they were created or updated.
Original source - Jun 15, 2026
- Date parsed from source:Jun 15, 2026
- First seen by Releasebot:Jul 6, 2026
2026.06.1
Okta Identity Engine adds broader device assurance support, spec-compliant client ID claims for AI agent tokens, secure token exchange for Salesforce requests, event hooks for AI agent APIs, and provisioning for Rapid7 InsightAppSec, expanding automation and security options for admins and developers.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Spec-compliant client ID claims for AI agent tokens
Okta Expression Language profiles now include the app.clientId property during user claim evaluations for AI agent OAuth 2.0 clients. This allows developers to generate spec-compliant tokens during AI agent flows.
OAuth secure token exchange for Salesforce requests
Okta for AI Agents now uses the OAuth 2.0 secure token exchange flow when it sends requests to the Salesforce app integration, resource server, or MCP server.
Event hooks for AI agent APIs
The AI agent APIs are now event hook-eligible, enabling Workflows to be triggered based on events. See Event hooks.
Provisioning for Rapid7 InsightAppSec
Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.
Original source
This is the end. You've seen all the release notes in this feed!
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.