Okta Identity Engine Updates & Release Notes
14 updates curated from 2 sources by the Releasebot Team. Last updated: Sep 1, 2026
- Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Sep 1, 2026
2026.08.3
Okta Identity Engine adds manual MCP server registration, expanded device assurance OS support, clearer AI agent app authentication requirements, and Jamf Pro integration updates that surface Application username format by default for custom SCIM userName mappings.
2026.08.3: Update 3 started deployment on August 31
Manual MCP registration
Admins can now manually configure authorization server details and client credentials when registering MCP servers. This allows registration of internal or legacy MCP servers that don't support automated metadata discovery endpoints. See Add MCP servers.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- macOS (26.6.2)
- iOS (26.6.1, 18.7.10)
- Windows 10 builds (10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663)
- Windows 11 builds (10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168)
Authentication requirement for AI agent app
When an AI agent is bound to an app, the User access tab now displays the authentication requirement for the app. It also provides a link to the app's Sign On tab where you can configure an authentication policy.
Jamf Pro integration updates
The Application username format field in the Admin Console now appears by default. This allows admins to configure custom mappings for the SCIM userName attribute.
Original source - Aug 25, 2026
- Date parsed from source:Aug 25, 2026
- First seen by Releasebot:Aug 26, 2026
- Modified by Releasebot:Sep 1, 2026
2026.08.2
Okta Identity Engine adds device assurance OS support, broader JA4 TLS fingerprinting, real-time import monitoring updates, and easier email from-address copying across brand domains, while Radius Agent 2.27 brings internal improvements and fixes.
2026.08.2: Update 2 started deployment on August 25
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- macOS 14.8.9
- macOS 15.7.9
- macOS 26.6.1
Radius Agent version 2.27
This version includes internal improvements and fixes.
JA4 TLS fingerprinting
Okta now captures JA4 TLS client fingerprints across Syslog event types (securityContext.tlsFingerprint.ja4 pr), instead of just a curated subset. This includes telephony events (for example, OTP/SMS delivery) along with sign-in, auth, and token events. This provides customers and Okta's security teams with fingerprint-level visibility to spot bot traffic, toll fraud, and other TLS-based attack patterns that IP/user-agent signals miss on their own.
This is not yet available for orgs on custom-hosted domains.
Enhanced import monitoring with real-time updates
You can now view real-time progress for imports from the Import Monitoring dashboard. This provides greater visibility into the current status of in-progress imports such as the number of data chunks currently being processed.
Copy email from-addresses to the default brand domain
You can now copy a custom email from-address to the default Okta domain when configuring brand email settings. Previously, this option was available only when copying between custom brands.
Original source All of your release notes in one feed
Join Releasebot and get updates from Okta and hundreds of other software products.
- Aug 17, 2026
- Date parsed from source:Aug 17, 2026
- First seen by Releasebot:Aug 19, 2026
2026.08.1
Okta Identity Engine releases device assurance updates, adding support for Android 14 through 17 in OS version policies, new IP service categories for enhanced dynamic zones, and Cross App Access for AI agents and apps for all customers with admin-managed access and direct user authentication options.
2026.08.1: Update 1 started deployment on August 17
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 14, 15, 16, 17 (2026-08-01)
New IP service categories for enhanced dynamic zones
Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
Cross App Access support for AI agents and apps for all customers
Use XAA to secure access between custom SSO-agentic requesting apps and SSO resource apps. XAA enables customers to connect AI agents and apps to take action on behalf of a user, and removes the need for user consent at runtime. The XAA connection is managed by Okta admins, providing them with visibility and control over which actions an AI agent can take on behalf of a user across the supported OIDC and SAML SSO protocols.
- For the agentic requesting app configuration, see Add AI agents manually, and select your SSO agentic app in User access > App used for access configuration.
- For the XAA resource app configuration, see Configure resource server connectors. If you're configuring an OIN resource app, it must already have XAA enabled.
- To connect the AI agent to the resource app, see Connect AI agents to resources and select Application as the resource type, and then select your resource app.
For agentic requesting apps that use OIDC for SSO, Okta enables binding an AI agent with an OIDC SSO app so that they share the same credentials. If you want to remove this configuration in Okta, delete the AI agent and the corresponding OIDC app.
From this AI agent-app binding capability, admins can now configure direct user authentication for the AI agent. If you have an Okta for AI Agent org and have previously used the Delegation tab to configure AI agent access through delegation links, you need to reconfigure them with the User access tab. See the Migration from Okta for AI Agent delegation link guidance.
Original source - Aug 14, 2026
- Date parsed from source:Aug 14, 2026
- First seen by Releasebot:Aug 7, 2026
- Modified by Releasebot:Aug 14, 2026
Version: 2026.08.0
Okta Identity Engine adds AI agent imports from Workday and Langsmith, expands app provisioning and SSO support, updates device assurance OS coverage, and improves admin and end-user experiences with stronger logs, smart card enrollment, passkey guidance, and new security controls.
Version: 2026.08.0
Import AI agents from Workday
You can now import and manage AI agents built in the Workday Agent System of Record (ASOR) directly through Okta. See AI agent imports.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Claude supports SAML 2.0 SSO
The Claude app integration now supports SAML 2.0 SSO. Orgs that are subscribed to Okta for AI Agents can continue using the integration to import Claude Managed Agents into Okta. See Integrate Claude with Okta.
Provisioning for Barracuda
Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.
Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
Agent-to-agent audience update
The agent-to-agent server resource url (audience parameter) can now be a free-form string.
Provisioning for Toggl
Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.
Provisioning for Moodle
Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.
Provisioning for HERE
Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.
Editable issuer URL for AI agent resource connections
Now when you create a resource connection between an AI agent and an authorization server, you can modify the authorization server's issuer URL.
Skipped failed entries during AI agent import
Now when you import AI agents from a provider, Okta skips the failed entries and creates or updates the successful ones.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 14, 15, 16, 17 (2026-07-01)
- Windows 10 builds (10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548)
- Windows 11 builds (10.0.22631.7376, 10.0.26100.8875, 10.0.26200.8875)
Import AI agents from Langsmith
You can now import and manage AI agents built in the Langsmith Deployments directly through Okta. See AI agent imports.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- macOS (26.6, 15.7.8, 14.8.8)
- iOS (26.6)
Improved smart card enrollment
Users can now enroll a smart card even if the login attribute doesn't match the value mapped from the card. Previously, enrollment failed during dynamic matching or Just-In-Time provisioning because the login attribute was treated as restricted from updates. See Add a Smart Card identity provider.
Okta Provisioning Agent, version 3.3.0
Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.
Okta Active Directory agent, version 3.23.0
This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.
New Research Release lifecycle
A new Research Release lifecycle is now available, marked with a Research Release banner in Okta admin documentation and visible in the Admin Console under Settings > Features. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.
Improved system log events for IdP routing
System log events for IdP routing now include the target information from the IdP Discovery rule that matched, when available.
New minimum character length for AI agent names
AI agent names now must contain a minimum of three characters.
Request subscriptions data export
To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.
New target for user.risk.detect events
Identity Threat Protection now populates affected factors in the user.risk.detect event's target for entity critical actions for high-threat IPs.
Malware Proxy Detection
Admins can now detect and control access from known malware proxy networks using a new MALWARE_PROXIES IP service category in Enhanced Dynamic Network Zones. This category is powered by Okta's CyberDefense, covering proxy services associated with malware and botnet activity (including 911 S5, NSOCKS, iProxy, BHProxies, and others). Admins can include or exclude MALWARE_PROXIES when configuring Enhanced Dynamic Network Zones, enabling more precise policies, for example, denying access through the global session policy or app sign-in policy for traffic originating from these proxy networks. See Supported IP service categories.
SAP SuccessFactors OAuth 2.0 with SAML Assertion
The SAP SuccessFactors app integration now supports OAuth 2.0 with SAML Assertion for enhanced API security. To ensure your provisioning and sync processes continue without interruption, you must migrate to this new authentication method before the SAP Basic Authentication deletion deadline on November 20, 2026. See Configure OAuth 2.0 with SAML for SAP SuccessFactors.
Okta Integration Wizard
Use the Okta Integration Wizard (OIW) to create and deploy custom app integrations in your Okta org. You can configure SSO, SCIM provisioning, Entitlement Management, Universal Logout, and custom API Integration Actions capabilities for the app integration. You can use the app integration as a template to create multiple app instances in your org without reconfiguring each app instance. This helps you manage your custom integrations more efficiently and avoid workarounds for SCIM and custom Workflows connectors. See Okta Integration Wizard.
Updated passkey enrollment screen
The passkey enrollment screen in the Sign-In Widget now includes updated copy and an informational image to help users understand what a passkey is before they enroll.
WebAuthn enrollment failure events in the System Log
The System Log now logs failed WebAuthn (FIDO2) enrollment attempts, using the user.mfa.factor.activate event and debug data such as AAGUID, isBackupEligible, and matched authenticator groups. Previously, only successful enrollments were logged. You can use this to identify which authenticator models don't enroll.
MCP Servers and Resource Servers moved to Applications and Resources
In the Admin Console, the MCP Servers and Resource Servers pages have moved from the Directory menu to the Applications and Resources menu.
Applications menu renamed to Applications and Resources
In the Admin Console, the Applications menu is now called Applications and Resources.
Direct End-User Settings access
Users may now access their Settings page through a direct URL in addition to the End-User Dashboard. This feature provides convenience and security for users, gives admins greater flexibility when working with End-User Dashboard access control scenarios, and includes accessibility and UX improvements. See End-User Settings.
Original source - August 2026
- No date parsed from source.
- First seen by Releasebot:Aug 13, 2026
- Modified by Releasebot:Aug 19, 2026
2026.08.0
Okta Identity Engine adds major AI agent management, cross-app access, and agent-to-agent connections, while expanding provisioning, device assurance, and security controls across Microsoft 365, Workday, Claude, and more. It also brings updates for sign-in, logging, and admin workflows.
Version: 2026.08.0
Import AI agents from Microsoft Office 365
You can now import and manage AI agents built in Microsoft Copilot Studio and Microsoft AI Foundry directly through Okta. See AI agent imports.
Import AI agents from Workday
You can now import and manage AI agents built in the Workday Agent System of Record (ASOR) directly through Okta. See AI agent imports.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Anthropic (Claude) SAML SSO integration
A new SAML 2.0 SSO integration for Anthropic (Claude) is now available on the Okta Integration Network, with the existing Anthropic AI Agent integration bundled in.
Claude supports SAML 2.0 SSO
The Claude app integration now supports SAML 2.0 SSO. Orgs that are subscribed to Okta for AI Agents can continue using the integration to import Claude Managed Agents into Okta. See Integrate Claude with Okta.
Provisioning for Barracuda
Provisioning is now available for the Barracuda WAF-as-a-Service app integration. See Integrate Barracuda WAF-as-a-Service with Okta.
Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
Sign-In Widget, version 7.47.1
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Agent-to-agent audience update
The agent-to-agent server resource url (audience parameter) can now be a free-form string.
Cross app access for AI agents and apps
Cross app access now secures connections between custom SAML requesting apps and OIDC/SAML resource apps. This feature allows admins to securely connect AI agents and apps to take action on behalf of users, bypassing the need for user consent. Admins retain full visibility and granular control over every action an AI agent can execute for a user. See Configure resource server connectors.
Provisioning for SafetyCulture
Provisioning is now available for the SafteyCulture app integration. See Integrate Safetyculture with Okta.
Provisioning for Toggl
Provisioning is now available for the Toggl app integration. See Integrate Toggl with Okta.
Provisioning for Moodle
Provisioning is now available for the Moodle app integration. See Integrate Moodle with Okta.
Agent-to-agent connections
Agent-to-agent server connections allow admins to connect AI agents to other AI agents. Admins can manage scopes to restrict access to the appropriate AI agent tasks, and allow service apps to call AI agents without user context. Using tokens and the System Log, admins can view all the users, AI agents, and apps that call an AI agent. See Agent-to-agent connections.
Provisioning for Elastic Search
Provisioning is now available for the Elastic Search app integration. See Integrate Elastic Search with Okta.
Provisioning for QualtricsXM
Provisioning is now available for the QualtricsXM app integration. See Integrate Qualtrics XM with Okta.
Provisioning for HERE
Provisioning is now available for the HERE app integration. See Integrate HERE with Okta.
Editable issuer URL for AI agent resource connections
Now when you create a resource connection between an AI agent and an authorization server, you can modify the authorization server's issuer URL.
Skipped failed entries during AI agent import
Now when you import AI agents from a provider, Okta skips the failed entries and creates or updates the successful ones.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 14, 15, 16, 17 (2026-07-01)
- Windows 10 builds (10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548)
- Windows 11 builds (10.0.22631.7376, 10.0.26100.8875, 10.0.26200.8875)
Import AI agents from Langsmith
You can now import and manage AI agents built in the Langsmith Deployments directly through Okta. See AI agent imports.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- macOS (26.6, 15.7.8, 14.8.8)
- iOS (26.6)
Sign-In Widget, versions 7.48.1 and 7.48.0
For details about these releases, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Improved smart card enrollment
Users can now enroll a smart card even if the login attribute doesn't match the value mapped from the card. Previously, enrollment failed during dynamic matching or Just-In-Time provisioning because the login attribute was treated as restricted from updates. See Add a Smart Card identity provider.
Okta Provisioning Agent, version 3.3.0
Okta Provisioning Agent 3.3.0 is now available. This release supports dynamic page size reduction during SCIM app imports, delta provisioning through PATCH requests, and automated entitlement removal during access certifications. Additionally, this version updates the bundled Amazon Corretto JRE to 17.0.19.10.1 and resolves a logging security issue. See Okta Provisioning Agent and SDK version history.
Okta Active Directory agent, version 3.23.0
This release of the Okta Active Directory agent updates the AD Agent Management Utility to guide administrators in granting minimum required permissions instead of prompting to add service accounts to the Domain Admins group. Additionally, the installer no longer halts during service account permission checks in misconfigured environments. This release also includes security enhancements and bug fixes. See Okta Active Directory agent version history.
New Research Release lifecycle
A new Research Release lifecycle, marked with a Research Release banner, is now available for Okta admin documentation. Research Release features are available exclusively to members of the Okta Research Partner Program for a fixed evaluation period, before a feature moves toward Early Access or General Availability. See Research Releases.
Improved system log events for IdP routing
System log events for IdP routing now include the target information from the IdP Discovery rule that matched, when available.
New minimum character length for AI agent names
AI agent names now must contain a minimum of three characters.
New Proxy service for enhanced dynamic zones
PROXYLINE_PROXY is now supported as an individual Proxy service category in enhanced dynamic zones. See Supported IP categories.
Request subscriptions data export
To export information about users subscribed to access requests, select the Request subscriptions option in the Export Data window. The Requests option no longer includes subscriber data. See Export data from Access Requests.
New target for user.risk.detect events
Identity Threat Protection now populates affected factors in the user.risk.detect event's target for entity critical actions for high-threat IPs.
New System Log events for Office 365 app-based provisioning
The System Log now logs the following events for app-based authentication for Office 365 provisioning:
- app.office365.provisioning_app.create: This event is logged when Okta creates a dedicated Microsoft Entra ID app that's registered and used for Office 365 provisioning.
- app.office365.provisioning_app_credential.rotate: This event is logged when Okta rotates the client secret of the registered Microsoft Entra ID app that's used for Office 365 provisioning. The Outcome field in this event's data indicates whether the client secret rotation was successful or not.
Advanced posture checks for device assurance
Advanced posture checks let admins configure specific device security conditions beyond what standard device assurance policies support. Using osquery, you can write custom SQL queries to assess device state on macOS and Windows devices, configure checks for unmanaged devices, and integrate with endpoint detection and response (EDR) tools. See Configure advanced posture checks for device assurance.
Strong cipher enforcement for X.509 client certificate authentication
Okta now enforces strong cryptographic ciphers for X.509 client certificates used in mTLS authentication. Client certificates signed with weak ciphers, such as RSA-1024, are no longer accepted for new orgs. If you use X.509 certificate-based authentication, ensure that your client certificates meet FIPS 140-2 cipher requirements.
Updated passkey enrollment screen
The passkey enrollment screen in the Sign-In Widget now includes updated copy and an informational image to help users understand what a passkey is before they enroll.
Customizable emails for Passkeys (FIDO2 WebAuthn) authenticator
The email that users receive when the admin configures a Passkeys (FIDO2 WebAuthn) authenticator is now available as a customizable template in Customizations Brands Emails. Admins can modify the subject line, email body, and dynamic variables such as the PIN, first name, and org name, and can add content in multiple languages.
Email auto-enrollment and recovery management
Admins can control the automatic enrollment of email as an authenticator and configure email-based password recovery, unlock, and change where email isn't an authenticator. See Make email an optional authenticator.
Application-based authentication for Office 365 provisioning
Okta now creates a dedicated app in your Microsoft Entra ID tenant instead of a service account for User Sync and Universal Sync provisioning. This app supports app-based authentication and helps improve your org's security. If you have existing User Sync or Universal Sync configurations, you must reauthenticate and consent to two new permissions by September 30, 2026. See Provide Microsoft admin consent for Okta.
MCP Servers and Resource Servers moved to Applications and Resources
In the Admin Console, the MCP Servers and Resource Servers pages have moved from the Directory menu to the Applications and Resources menu.
Applications menu renamed to Applications and Resources
In the Admin Console, the Applications menu is now called Applications and Resources.
Enhanced Breached Credentials Protection
This feature provides a premium breached credentials detection feed for Okta Customer Identity (OCI) customers with Identity Threat Protection which identifies more compromised credentials sooner. See Breached credentials protection.
Update group rule assignments
Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.
Import unlicensed users from Azure Active Directory to Okta
You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.
Identity verification with vendor-submitted integrations
Identity verification (IDV) vendors can now submit integrations through the Okta Integration Network. You can configure and apply these integrations to your authentication policies to verify user identities.
On-demand rotation of Office 365 SSO signing certificates
Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.
Original source Similar to Okta Identity Engine with recent updates:
- Claude Code updates437 release notes · Latest Sep 5, 2026
- Claude updates136 release notes · Latest Sep 2, 2026
- Anthropic updates61 release notes · Latest Sep 1, 2026
- Okta for AI Agents updates15 release notes · Latest Aug 1, 2026
- Google Workspace updates58 release notes · Latest Sep 4, 2026
- Gemini updates408 release notes · Latest Sep 4, 2026
- Aug 3, 2026
- Date parsed from source:Aug 3, 2026
- First seen by Releasebot:Aug 7, 2026
2026.07.3
Okta Identity Engine releases editable issuer URLs for AI agent resource connections, better AI agent imports, broader device assurance OS support, and fixes for authentication, admin console, reporting, and system log issues. It also adds and updates several Okta Integration Network connectors.
Generally Available
Editable issuer URL for AI agent resource connections
Now when you create a resource connection between an AI agent and an authorization server, you can modify the authorization server's issuer URL.
Skipped failed entries during AI agent import
Now when you import AI agents from a provider, Okta skips the failed entries and creates or updates the successful ones.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 14, 15, 16, 17 (2026-07-01)
- Windows 10 builds (10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548)
- Windows 11 builds (10.0.22631.7376, 10.0.26100.8875, 10.0.26200.8875)
Early Access
Removal of Cross App Access configuration using Managed Connection
The removal of the ability to configure cross app access from the Managed connection tab located on the app's profile page is scheduled for an upcoming release. When it's removed, your existing configurations will stop working. Reconfigure your connections from the Resource Server tab to avoid disruptions. See Connect AI agents to resources.
Fixes
- When admins reassigned Google Workspace licenses to users, the process occasionally failed and returned a task error in Okta. (OKTA-1074226)
- When admins configured the app setting When a user is deactivated in the app to Do nothing alongside a Post-Termination Interval, user imports from SuccessFactors failed to unassign terminated users. (OKTA-1115401)
- In My Settings, the accessible label for the org logo link didn't match the visible label text. (OKTA-1164496)
- Users who originally enrolled a YubiKey without a PIN, but later set a PIN externally, received an error when an authentication policy rule required a device passcode or biometric verification. (OKTA-1187996)
- When users clicked the privacy policy link in the Sign-in Widget, they were redirected to the sign-in page instead of the privacy policy page. (OKTA-1201388)
- The System Log incorrectly logged VPN Notification Settings updated as the reason when the Display icon to users setting was enabled or disabled for a custom OIDC app. (OKTA-1203429)
- In some orgs, users couldn't authenticate through their IdP, even though Trust claims from this identity provider was enabled and the IdP had already satisfied the authentication policy's phishing-resistant requirement. (OKTA-1204547)
- Some admins saw 500 errors when they tried to delete authorization servers in bulk. (OKTA-1208896)
- Some admins saw 500 errors when they tried to delete authorization servers in bulk. (OKTA-1208896)
- In some orgs, when admins created an OIDC web app, the client credentials grant type didn't appear, even though the correct feature flags were enabled. (OKTA-1221984)
- Session context change events in the System Log showed blank display names when a rate limit was exceeded. (OKTA-1226680)
- The Okta password health report timed out for orgs with large user directories and returned incomplete data. Reports for large orgs are now limited to a maximum of 500,000 users to ensure reliable performance. (OKTA-1151306)
- The Identity Governance pages had several spelling and punctuation errors. (OKTA-1163458)
- When admins ran an individual realm assignment job, the evaluation process stopped after encountering a single user evaluation failure. (OKTA-1193971)
- In the Admin Console, when admins configured protected actions, the UI displayed both Reset factors for super admins and Reset authenticators for super admins simultaneously. (OKTA-1205255)
- When admins enabled user provisioning features in SCIM 1.0 using On-Premises Provisioning, the schema discovery flow broke. (OKTA-1210290)
- Deleted AI agent providers still appeared on the AI agent providers screen and in the AI agent provider filter on the AI agents screen. (OKTA-1211699)
- Admins could create a custom token claim named ver for an OpenID Connect app, even though ver is a reserved claim in the ID token. (OKTA-1222755)
- In orgs with both Identity Threat Protection and Policy Change Management enabled, admins saw an error message when they tried to roll back a policy branch. (OKTA-1227194)
- In orgs that use an external IdP as an authentication factor, claims from those IdPs weren't shared with downstream apps. (OKTA-1231193)
Okta Integration Network
- Airbyte Lifecycle Management Connector by Redblock (SCIM) was updated with a new app name and description.
- Cisco User Management Connector (SAML) is now available. Learn more.
- Clarion by Cantina (API Service) has the okta.groups.manage scope.
- DeleteMe (SCIM) has updated endpoints. Learn more.
- Emergent (SAML) is now available. Learn more.
- GreyMatter Transit (API Service) is now available. Learn more.
- Spark HR (OIDC) is now available. Learn more.
- Spark HR (SCIM) is now available. Learn more.
- SpotDraft (SCIM) was updated. Learn more.
- Aug 3, 2026
- Date parsed from source:Aug 3, 2026
- First seen by Releasebot:Aug 5, 2026
2026.07.3
Okta Identity Engine adds more flexibility for AI agent connections with editable issuer URLs, improves AI agent imports by skipping failed entries and keeping successful ones, and expands device assurance support with new Android and Windows OS versions.
Editable issuer URL for AI agent resource connections
Now when you create a resource connection between an AI agent and an authorization server, you can modify the authorization server's issuer URL.
Skipped failed entries during AI agent import
Now when you import AI agents from a provider, Okta skips the failed entries and creates or updates the successful ones.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 14, 15, 16, 17 (2026-07-01)
- Windows 10 builds (10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548)
- Windows 11 builds (10.0.22631.7376, 10.0.26100.8875, 10.0.26200.8875)
- Jul 21, 2026
- Date parsed from source:Jul 21, 2026
- First seen by Releasebot:Jul 22, 2026
- Modified by Releasebot:Aug 7, 2026
2026.07.2
Okta Identity Engine releases new device visibility for macOS and Windows, cross app access for AI agents and apps, and an update that lets agent-to-agent audience values use free-form strings. It also includes multiple fixes and new Okta Integration Network app availability.
Generally Available
Sign-In Widget, version 7.47.1
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Agent-to-agent audience update
The agent-to-agent server resource url (audience parameter) can now be a free-form string.
Device Visibility feature for macOS and Windows
Device Visibility replaces the basic detail page for managed devices with a new four-tab view for macOS and Windows devices. It surfaces OS-level user accounts, Platform SSO and Okta FastPass enrollment status, Okta Verify version, and device security signals in one place. This makes it easier for IT and security admins to verify authenticator enrollment and assess device security posture without piecing together information from multiple screens. See View device details.
Cross app access for AI agents and apps
Cross app access now secures connections between custom SAML requesting apps and OIDC/SAML resource apps. This feature allows admins to securely connect AI agents and apps to take action on behalf of users, bypassing the need for user consent. Admins retain full visibility and granular control over every action an AI agent can execute for a user. See Configure resource server connectors.
Fixes
- In Profile Editor, when an admin clicked the info icon next to the Licenses attribute for the Google app, the Attribute members list became editable instead of read-only. (OKTA-182607)
- When an admin created a user and selected Activate later, an error appeared and the user wasn't created. (OKTA-701601)
- Push notifications for Okta Verify challenges during direct authentication sometimes failed with a direct_auth_policy_denied error when biometric verification wasn't enrolled. (OKTA-1099950)
- On the End-User Settings page in orgs with language localization, the non-breaking space before the colon in error messages was missing. (OKTA-1113766)
- ITP couldn't successfully complete continuous policy evaluation when Trusted App Filters were configured as part of the app sign-in policies. (OKTA-1123314)
- In the Secure Partner Access Admin Portal, profile attributes from external IdPs incorrectly appeared as editable fields. (OKTA-1124860)
- Client IP and request IP chain data were missing from the user.account.update_password System Log events. (OKTA-1156514)
- On iOS devices without an SSO extension, users in some orgs saw an error message during account recovery or unlock instead of being challenged with Okta FastPass. (OKTA-1162026)
- The support link on the Sign-In Widget didn't meet the minimum color contrast ratio. (OKTA-1164541)
- When a user updated their password from their End-User Dashboard, the new password didn't sync to the assigned Jamf Pro app unless they had the Manage app permission. (OKTA-1183563)
- Some users saw an error when they tried to sign in with Okta FastPass. (OKTA-1185557)
- When an on-premises provisioning operation failed, the resulting error message displayed an inaccurate error code. (OKTA-1199729)
- When admins attempted to reassign a user to a custom app that used on-premises provisioning, the reactivation request failed. (OKTA-1210786)
- Admins could add invalid app names to an AI agent's user sign-on delegations. (OKTA-1212527)
- When an Okta Classic Engine org was migrated to Identity Engine and the email authenticator was then deleted, self-service registration incorrectly required end users to enroll a non-email authenticator. (OKTA-1216937)
- In some orgs, when admins created an OIDC web app, the client credentials grant type didn't appear, even though the correct feature flags were enabled. (OKTA-1221984)
- The external link icon on the My Settings > Recent activity page didn't have alt text. (OKTA-1221994)
- In orgs that use an external IdP as an authentication factor, claims from those IdPs weren't shared with downstream apps. (OKTA-1231193)
- During imports from Salesforce, Okta failed to process entitlement changes when Group or Role entitlement IDs were updated in Salesforce. (OKTA-1231515)
Okta Integration Network
- Airbyte by Redblock (SCIM) is now available. Learn more.
- Bitwarden (OIDC) is now available. Learn more.
- Bitwarden (SAML) is now available. Learn more.
- Cribl Cloud (SAML) is now available. Learn more.
- KnowledgeOwl Author Provisioning (SCIM) is now available. Learn more.
- Levenza (SAML) has a new app name, description, icon, and integration guide.
- Lolipop! Static IP Access (SCIM) is now available. Learn more.
- Rapid7 InsightAppSec (SAML) has a new app name.
- SafetyCulture (SAML) is now available. Learn more.
- SparkToro (OIDC) is now available. Learn more.
- SparkToro (SCIM) is now available. Learn more.
- Toggl (SAML) is now available. Learn more.
- Jul 13, 2026
- Date parsed from source:Jul 13, 2026
- First seen by Releasebot:Jul 15, 2026
- Modified by Releasebot:Aug 7, 2026
2026.07.1
Okta Identity Engine adds GA AI agent imports from Microsoft Office 365, new Android 13 to 16 support for device assurance, Anthropic Claude SAML SSO, and provisioning for Linear and Appspace, with fixes and Okta Integration Network updates.
Generally Available
Import AI agents from Microsoft Office 365
You can now import and manage AI agents built in Microsoft Copilot Studio and Microsoft AI Foundry directly through Okta. See AI agent imports.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Anthropic (Claude) SAML SSO integration
A new SAML 2.0 SSO integration for Anthropic (Claude) is now in the Okta Integration Network. This integration includes the existing Anthropic AI Agent. This feature is available to customers who have Okta for AI Agents. See Integrate Claude with Okta.
Provisioning for Linear
Linear provisioning is now available. See Create Linear integration.
Provisioning for Appspace
Provisioning is now available for the Appspace app integration. When you provision the app, you can enable security features like Entitlement Management. See Integrate Appspace with Okta.
Fixes
- When the display language was set to Japanese, the people/groups counts on the People and Groups pages weren't translated. (OKTA-926579)
- In Profile Editor, super admins could set a custom user type as default by modifying the isDefault field in the network payload. (OKTA-991083)
- On the End-User Settings page in orgs with language localization, the non-breaking space before the colon in error messages was missing. (OKTA-1113766)
- The focus indicator on Recent Activity sign-in accordions in My Settings didn't meet the required 3:1 contrast ratio. (OKTA-1164470)
- The autocomplete attribute was missing from personal information fields in My Settings. (OKTA-1164492)
- During installation, the LDAP Agent (version 5.26.0) incorrectly displayed its version number as the latest Active Directory Agent version (3.22.0). (OKTA-1166327)
- During the sign-in flow, some users with certain phone authenticator enrollments encountered a system error when they initiated a phone verification challenge. (OKTA-1178849)
- The authorization server returned an incorrect issuer value when it processed concurrent OAuth sign-in requests through a custom domain. (OKTA-1197523)
- The OAuth secure token exchange (STS) fields were visible for resource server apps that don't support the STS protocol. (OKTA-1210264)
Okta Integration Network
- AppLovin (SWA) was updated.
- CallPlease has two new ACS URLs and a new configuration guide. Learn more.
- Glean (OIDC) is now available. Learn more.
- Stack Internal (SAML) was updated. Learn more.
- Willow (OIDC) is now available. Learn More.
- Jul 7, 2026
- Date parsed from source:Jul 7, 2026
- First seen by Releasebot:Jul 7, 2026
2026.07.0
Okta Identity Engine adds broader AI agent management, device assurance, and access request updates, with new support for AI agent imports, roles, event hooks, and secure token exchange. It also expands provisioning, group and certificate controls, plus new OS support and threat protection improvements.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Spec-compliant client ID claims for AI agent tokens
Okta Expression Language profiles now include the app.clientId property during user claim evaluations for AI agent OAuth 2.0 clients. This allows developers to generate spec-compliant tokens during AI agent flows.
OAuth secure token exchange for Salesforce requests
Okta for AI Agents now uses the OAuth 2.0 secure token exchange flow when it sends requests to the Salesforce app integration, resource server, or MCP server.
AI agent events are now event-hook eligible
The AI agent and AI agent provider events are now event-hook eligible, enabling Workflows to be triggered based on events. See Event hooks.
Provisioning for Rapid7 InsightAppSec
Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.
Reassign steps to multiple users
You can now reassign steps within an approval sequence or request type to 10 users. This applies to tasks, questions, actions, and approvals.
Admin OIDC App Phase Two Tranch One
When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.
Sign-In Widget, version 7.46.2
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Unique client authorization settings required for OIN apps
When you enter client authorization details for an app integration, an error now appears if another integration already uses those details.
New protocol runtime for Amazon Bedrock AgentCore AI agents
You can now import both standard HTTP and agent-to-agent protocol runtimes from the Amazon Bedrock AgentCore platform.
MCP servers active by default
Newly created MCP servers are now in an active state by default. See Add MCP servers.
AI agent admin role
Super admins can now delegate AI agent management tasks using the new AI agent admin role. Admins with this role can perform tasks like registering AI agents, assigning owners, and configuring resource connections. See Manage Okta for AI Agents admin roles.
Date range filter for AI agents
The AI Agents page now provides a date range filter so admins can filter AI agents by when they were created or updated.
Import AI agents from Google Vertex AI
You can now import and manage AI agents built in Google Vertex AI directly through Okta. See Configure Google Vertex AI for AI agent imports.
Sign-In Widget, version 7.46.3
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 17 (2026-06-01)
- Windows 10 builds (10.0.17763.8880, 10.0.19044.7417, 10.0.19045.7417)
- Windows 11 builds (10.0.22631.7219, 10.0.26100.8655, 10.0.26200.8655)
UI updates to Okta Access Requests web app
The All requests page in the Okta Access Requests web app now shows 999+ count if there are 1000 or more requests instead of giving the count. This change helps reduce the time taken to list the requests on the page.
Import Azure Active Directory users with null first and last name
You can now import users from Microsoft Azure Active Directory (AAD) who have null first name and last name values. This provides admins with a centralized view of their AAD users within Okta. See Import users to Office 365 using Microsoft Graph API.
Removal of search filters from the Inbox page
The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.
Okta for AI Agents UI updates
The AI agents page now provides Owner and Platform filters. Also, the AI agent providers page now has Registered AI agents column that displays the number of AI agents that are registered from the provider.
Suspicious Login Using A Sprayed Password
This detection indicates that a user's password has been identified in a password spray campaign and used to successfullly sign in. The detection enables ITP to trigger configured remediation actions such as Universal Logout or password reset through a workflow. See Suspicious login using a sprayed password.
This feature is following a slow rollout process.
Bot protection
Bot protection enables orgs to automatically identify and mitigate bot traffic by configuring remediation actions within the Identity Threat Protection (ITP) landing page. See Bot protection.
New VPN service for enhanced dynamic zones
The VIGOR_SSL_VPN is now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
AI agents admin role help link
On the Administrators Roles tab, the AI agents admin role now has a help link.
Maximum number of IDPs in an IDP routing rule increased
The maximum number of allowed IdPs in an IdP routing rule has been increased to 100. See Configure identity provider routing rules.
Advanced posture checks for device assurance
Advanced posture checks let admins configure specific device security conditions beyond what standard device assurance policies support. Using osquery, you can write custom SQL queries to assess device state on macOS and Windows devices, configure checks for unmanaged devices, and integrate with endpoint detection and response (EDR) tools. See Configure advanced posture checks for device assurance.
Okta SSF Transmitter now available to CIAM orgs
Okta uses CAEP to send security-related events and other data-subject signals to third-party security vendors. See Shared Signals Framework.
This feature is now available to Customer Identity and Access Management orgs.
Improved MFA enrollment policy validator
Orgs that have no self-initiated user.account.update_password syslog events over last 30 days are now excluded from the MFA enrollment policy validator warning triggered during the Okta Identity Engine upgrade, making it easier to upgrade.
Clear Managed Chrome Profile Browsing Data
Clear Managed Chrome Profile Browsing Data provides real-time remediation by instantly purging local session data (cookies and cache) within managed Chrome profiles upon ITP detection. By transforming the browser into a policy-enforced workspace, it ensures immediate, automated protection. See Clear managed Chrome profile browsing data.
Import unlicensed users from Azure Active Directory to Okta
You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.
Role-assignable push groups for Office 365
When you create a new push group for the Office 365 app integration, select the Is this role assignable checkbox to make the group role assignable in Microsoft Entra ID. This allows you to push Okta groups to Microsoft Entra ID and assign roles instead of manually creating groups in Entra ID and then linking them to Okta using push groups. See Configure Push Group.
Group push support in API Integration Actions apps
Apps that use API Integration Actions to perform provisioning can now use the Group Push feature. This enables the group import functionality for apps that use group API contracts in their provisioning actions.
Native to Web SSO
Native to Web SSO creates a seamless, unified authentication experience when a user transitions from an OIDC app (like a native or web app) to a web app (either OIDC or SAML). This feature uses standard, web-based federation protocols like SAML and OpenID Connect that help bridge the gap between two different application environments, using a single-use, one-way interclient trust SSO token. This eliminates repeating already provided sign-on assurances, and simplifies development by reducing authentication complexity. See Configure Native to Web SSO.
DirSync group imports for Active Directory
For Active Directory (AD) integrations, the Provisioning tab now provides an Enable imports with AD using DirSync checkbox. When you enable the checkbox, admins can perform incremental group imports using DirSync. See Configure Active Directory import and account settings.
ITP detections for AMFA orgs
Adaptive MFA orgs now benefit from ITP detections on sessions and entity users when these are detected on directly assigned super admins. These detection events are actionable using Workflows. This feature aligns with the Okta Secure Identity Commitment. See Identity Threat Protection events in System Log.
This feature is now available to Okta for US Military customers.
On-demand rotation of Office 365 SSO signing certificates
Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.
Update group rule assignments
Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.
Original source - July 2026
- No date parsed from source.
- First seen by Releasebot:Jul 6, 2026
Version: 2026.07.0
Okta Identity Engine adds AI agent, device assurance, and admin experience updates, including new AI agent roles and imports, stronger token and certificate controls, expanded OS support, advanced posture checks, improved MFA and group rule management, and user and email settings enhancements.
Version: 2026.07.0
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Spec-compliant client ID claims for AI agent tokens
Okta Expression Language profiles now include the app.clientId property during user claim evaluations for AI agent OAuth 2.0 clients. This allows developers to generate spec-compliant tokens during AI agent flows.
OAuth secure token exchange for Salesforce requests
Okta for AI Agents now uses the OAuth 2.0 secure token exchange flow when it sends requests to the Salesforce app integration, resource server, or MCP server.
AI agent events are now event-hook eligible
The AI agent and AI agent provider events are now event-hook eligible, enabling Workflows to be triggered based on events. See Event hooks.
Provisioning for Rapid7 InsightAppSec
Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.
Admin OIDC App Phase Two Tranch One
When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.
Unique client authorization settings required for OIN apps
When you enter client authorization details for an app integration, an error now appears if another integration already uses those details.
New protocol runtime for Amazon Bedrock AgentCore AI agents
You can now import both standard HTTP and agent-to-agent protocol runtimes from the Amazon Bedrock AgentCore platform.
MCP servers active by default
Newly created MCP servers are now in an active state by default. See Add MCP servers.
AI agent admin role
Super admins can now delegate AI agent management tasks using the new AI agent admin role. Admins with this role can perform tasks like registering AI agents, assigning owners, and configuring resource connections. See Manage Okta for AI Agents admin roles.
Date range filter for AI agents
The AI Agents page now provides a date range filter so admins can filter AI agents by when they were created or updated.
Import AI agents from Google Vertex AI
You can now import and manage AI agents built in Google Vertex AI directly through Okta. See Configure Google Vertex AI for AI agent imports.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 17 (2026-06-01)
- Windows 10 builds (10.0.17763.8880, 10.0.19044.7417, 10.0.19045.7417)
- Windows 11 builds (10.0.22631.7219, 10.0.26100.8655, 10.0.26200.8655)
Removal of search filters from the Inbox page
The Requester type and Follower options have been removed from Filters on the Inbox page of the Okta Access Requests web app to improve performance.
Okta for AI Agents UI updates
The AI agents page now provides Owner and Platform filters. Also, the AI agent providers page now has Registered AI agents column that displays the number of AI agents that are registered from the provider.
Suspicious Login Using A Sprayed Password
This detection indicates that a user's password has been identified in a password spray campaign and used to successfullly sign in. The detection enables ITP to trigger configured remediation actions such as Universal Logout or password reset through a workflow. See Suspicious login using a sprayed password. This feature is following a slow rollout process.
New VPN service for enhanced dynamic zones
The VIGOR_SSL_VPN is now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.
AI agents admin role help link
On the Administrators Roles tab, the AI agents admin role now has a help link.
Strong cipher enforcement for X.509 client certificate authentication
Okta now enforces strong cryptographic ciphers for X.509 client certificates used in mTLS authentication. Client certificates signed with weak ciphers, such as RSA-1024, are no longer accepted for new orgs. If you use X.509 certificate-based authentication, ensure that your client certificates meet FIPS 140-2 cipher requirements.
Customizable emails for Passkeys (FIDO2 WebAuthn) authenticator
The email that users receive when the admin configures a Passkeys (FIDO2 WebAuthn) authenticator is now available as a customizable template in Customizations Brands Emails. Admins can modify the subject line, email body, and dynamic variables such as the PIN, first name, and org name, and can add content in multiple languages.
Email auto-enrollment and recovery management
Admins can control the automatic enrollment of email as an authenticator and configure email-based password recovery, unlock, and change where email is not an authenticator. See Make email an optional authenticator.
Advanced posture checks for device assurance
Advanced posture checks let admins configure specific device security conditions beyond what standard device assurance policies support. Using osquery, you can write custom SQL queries to assess device state on macOS and Windows devices, configure checks for unmanaged devices, and integrate with endpoint detection and response (EDR) tools. See Configure advanced posture checks for device assurance.
Update group rule assignments
Admins can now update the groups assigned to a group rule without deleting and recreating the rule. This streamlines the management of group memberships and rule conditions. See Edit group rules.
Improved MFA enrollment policy validator
Orgs that have no self-initiated user.account.update_password syslog events over last 30 days are now excluded from the MFA enrollment policy validator warning triggered during the Okta Identity Engine upgrade, making it easier to upgrade.
Import unlicensed users from Azure Active Directory to Okta
You can now import users from Microsoft Azure Active Directory (AAD) who don't have an assigned Office 365 license. This allows admins to centralize their workforce lifecycle within Okta and eliminates the need to manage unlicensed accounts across both platforms. See Import users to Office 365 using Microsoft Graph API.
Group push support in API Integration Actions apps
Apps that use API Integration Actions to perform provisioning can now use the Group Push feature. This enables the group import functionality for apps that use group API contracts in their provisioning actions.
ITP detections for AMFA orgs
Adaptive MFA orgs now benefit from ITP detections on sessions and entity users when these are detected on directly assigned super admins. These detection events are actionable using Workflows. This feature aligns with the Okta Secure Identity Commitment. See Identity Threat Protection events in System Log. This feature is now available to Okta for US Military customers.
On-demand rotation of Office 365 SSO signing certificates
Office 365 app integrations that use WS-Federation for authentication now support the use of app-level certificates. Switching from org-level certificates to app-level certificates improves your security outcomes by eliminating a single point of failure if a shared org-level certificate expires. UI updates enable IT admins to easily monitor certificate status, generate certificates on demand, and perform certificate rotations without disrupting operations. See Configure Single Sign-On for Office 365.
Direct End-User Settings access
Users may now access their Settings page through a direct URL in addition to the End-User Dashboard. This feature provides convenience and security for users, gives admins greater flexibility when working with End-User Dashboard access control scenarios, and includes accessibility and UX improvements. See End-User Settings.
Original source - Jun 29, 2026
- Date parsed from source:Jun 29, 2026
- First seen by Releasebot:Jul 6, 2026
2026.06.3
Okta Identity Engine adds support for importing and managing AI agents built in Google Vertex AI, updates the Sign-In Widget to version 7.46.3, and expands device assurance OS support with new Android and Windows build coverage.
Import AI agents from Google Vertex AI
You can now import and manage AI agents built in Google Vertex AI directly through Okta. See Configure Google Vertex AI for AI agent imports.
Sign-In Widget, version 7.46.3
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 17 (2026-06-01)
- Windows 10 builds (10.0.17763.8880, 10.0.19044.7417, 10.0.19045.7417)
- Windows 11 builds (10.0.22631.7219, 10.0.26100.8655, 10.0.26200.8655)
- Jun 23, 2026
- Date parsed from source:Jun 23, 2026
- First seen by Releasebot:Jul 6, 2026
2026.06.2
Okta Identity Engine adds step reassignment for up to 10 users, new admin OIDC sign-in behavior, stricter OIN app client authorization checks, Bedrock AgentCore runtime imports, default-active MCP servers, and a date range filter for AI agents.
Reassign steps to multiple users
You can now reassign steps within an approval sequence or request type to 10 users. This applies to tasks, questions, actions, and approvals.
Admin OIDC App Phase Two Tranch One
When the Admin OIDC App Phase Two Tranch One feature is enabled, the Okta Admin Console automatically initiates the OIDC sign-in flow on page load, and admins are briefly redirected to the authentication page before the requested page appears.
Sign-In Widget, version 7.46.2
For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.
Unique client authorization settings required for OIN apps
When you enter client authorization details for an app integration, an error now appears if another integration already uses those details.
New protocol runtime for Amazon Bedrock AgentCore AI agents
You can now import both standard HTTP and agent-to-agent protocol runtimes from the Amazon Bedrock AgentCore platform.
MCP servers active by default
Newly created MCP servers are now in an active state by default. See Add MCP servers.
Date range filter for AI agents
The AI Agents page now provides a date range filter so admins can filter AI agents by when they were created or updated.
Original source - Jun 15, 2026
- Date parsed from source:Jun 15, 2026
- First seen by Releasebot:Jul 6, 2026
2026.06.1
Okta Identity Engine adds broader device assurance support, spec-compliant client ID claims for AI agent tokens, secure token exchange for Salesforce requests, event hooks for AI agent APIs, and provisioning for Rapid7 InsightAppSec, expanding automation and security options for admins and developers.
Device assurance OS version update
The following OS versions are now supported in device assurance policies:
- Android 13, 14, 15, 16 security patch 2026-01-05
Spec-compliant client ID claims for AI agent tokens
Okta Expression Language profiles now include the app.clientId property during user claim evaluations for AI agent OAuth 2.0 clients. This allows developers to generate spec-compliant tokens during AI agent flows.
OAuth secure token exchange for Salesforce requests
Okta for AI Agents now uses the OAuth 2.0 secure token exchange flow when it sends requests to the Salesforce app integration, resource server, or MCP server.
Event hooks for AI agent APIs
The AI agent APIs are now event hook-eligible, enabling Workflows to be triggered based on events. See Event hooks.
Provisioning for Rapid7 InsightAppSec
Provisioning is now available for the Rapid7 InsightAppSec app integration. When you provision the app, you can enable security features like Entitlement Management. See Rapid7 InsightAppSec.
Original source
This is the end. You've seen all the release notes in this feed!
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.