Zum Inhalt springen

Okta Release Notes

28 Einträge aus 4 Quellen. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Okta Classic Engine von Okta

Okta Classic Engine 2026.09.2: Begründungsfelder und Kong-AI-Provisioning

Okta Classic Engine 2026.09.2 ermöglicht in Okta Identity Governance konfigurierbare Begründungsfelder für Entscheidungen bei Access Requests, stellt Provisioning für die Kong-AI-Integration bereit und behebt Fehler wie falsche ROLE_ASSIGNED_USER_ACTIVATION-Audit-Ereignisse, langsames Laden der User-Sources-Seite und inkonsistente Anzeige des Drittanbieter-Admin-Status im Admin-Role-Assignment-Report.

Access Requests decision justification

Okta Identity Governance now supports configurable justification controls for access request decisions, providing requesters more transparency into their approvals and denials. Admins can configure the approval sequence or request type settings to include the decision justification field for approval tasks, allowing approvers the option to provide a rationale for their decision. All submitted justification text is captured on the request ticket and made available to the requester, providing insight into access decisions. See Request type settings.

Provisioning for Kong AI

Provisioning is now available for the Kong AI integration. See Integrate Kong AI with Okta.

Fixes

  • When an import job reconciled existing active admin users, Okta incorrectly logged false ROLE_ASSIGNED_USER_ACTIVATION audit events. This issue created misleading records when no role changes occurred. (OKTA-1274235)

  • The User Sources page loaded slowly if there was a large number of profile sources. (OKTA-1265698)

  • When generating the Out-of-the-Box Admin Role Assignment report, the third-party admin status appeared inconsistently for users with multiple admin roles assigned through group memberships. (OKTA-1278183) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Okta Classic Engine von Okta

Okta Classic Engine 2026.09.1: Manager-Aufgaben und Status-Timeline

Okta Classic Engine 2026.09.1 weist bei einem Managerwechsel offene Manager-Aufgaben und -Fragen in Access Requests automatisch dem neuen Manager zu, bietet Anfragenden eine Status-Timeline für ihre Aufgaben und behebt mehrere Fehler, darunter mehrfache user.mfa.factor.update-Ereignisse nach Okta-Verify-Updates auf iOS und ein fehlerhaftes Profil-Update aller Active-Directory-Benutzer beim Import eines einzelnen Service-Accounts.

Automatic tasks and questions reassignment after a manager change

To prevent access requests from being blocked during organizational changes, Okta Access Requests now automatically reassigns pending manager tasks and manager questions to an employee's new manager whenever a manager change occurs. This automated reassignment ensures that approvals proceed without manual IT intervention or delays, even if the previous manager's account has already been deactivated. This is available for requests built with both request conditions and request types.

Requester timeline view

Requesters can now view a detailed status timeline of their request's tasks directly from the Okta Access Request app. This enhanced visibility allows requesters to easily track the progress of their requests, see who has approved individual tasks, and identify remaining tasks, helping users stay informed throughout the approval process and reducing unnecessary status inquiries. The timeline is available for requests built with access request conditions.

Fixes

  • When users updated the Okta Verify app on iOS devices, the System Log recorded multiple user.mfa.factor.update events within a single day. (OKTA-1215063)

  • When an admin begin a user import for a single service account without an Okta user object, the profile sync process incorrectly updated all users in the Active Directory instance. (OKTA-1267422) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.09.3: Datenbank-Support allgemein verfügbar

Okta Privileged Access für Datenbanken ist jetzt allgemein verfügbar (GA) und entdeckt automatisch Datenbank-Benutzerkonten, rotiert und verwahrt Zugangsdaten und erzwingt richtlinienbasierte Multi-Faktor-Authentifizierung oder manuelle Genehmigungen.

Deployment date: Sep 28, 2026

Release summary

The following releases are now in Production:

Database privileged access management (GA)

Okta Privileged Access for databases helps minimize security risks by automatically discovering database user accounts, rotating and vaulting credentials, and enforcing policy-based multi-factor authentication or manual approvals for access. See Database integrations.

Previous releases

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.09.2: Automatische Bereitstellung in der Org

Okta Privileged Access wird bei aktivem Abonnement nun automatisch in der Org bereitgestellt, ohne dass die App manuell aus dem OIN-Katalog hinzugefügt oder SCIM-Provisionierung konfiguriert werden muss.

Deployment date: Sep 14, 2026

Release summary

The following releases are now in Production:

Okta Privileged Access automated app provisioning

Okta Privileged Access is now automatically provisioned in your org when your subscription becomes active. You no longer need to manually add the app from the OIN catalog or configure SCIM provisioning. See Set up Okta Privileged Access.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.09.1: AD-Passwörter per Workload-Rollen

Mit Workload-Rollen lassen sich per API-Key-Authentifizierung nun Passwörter von Active Directory-Konten anzeigen und rotieren.

Deployment date: Sep 09, 2026

Release summary

The following releases are now in Production:

Reveal Active Directory account passwords with workload roles

You can now use workload roles to reveal and rotate passwords for Active Directory accounts through API key authentication.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.09.0: Assignments mit dynamischen Richtlinien

In der Preview (EA) können Security-Admins mit Assignments den Zugriff auf privilegierte Ressourcen skaliert verwalten, wobei dynamische Richtlinien tausende statische Zuweisungen ersetzen.

Deployment date: Sep 03, 2026

Release summary

The following releases are now in Preview:

Simplified privileged access management with Assignments (EA)

Security admins can now use Assignments in Okta Privileged Access to streamline and manage access to privileged resources at scale. This relationship-aware model reduces redundant permission records by replacing thousands of static assignments with dynamic policies. See Assignments and relationships.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.08.5: Passwörter ohne Synchronisierung setzen

Passwörter für Active Directory-, SaaS- und Okta-Universal-Directory-Servicekonten lassen sich jetzt ohne Synchronisierung mit dem Zielsystem setzen, außerdem gibt es in der Preview Massen-Passwortrotation für bis zu 100 Active Directory-Konten (EA) und Workload-Zugriffskontrolle für Secrets.

Deployment date: August 31, 2026

Release summary

The following releases are now in Production:

Manual password configuration for resource credentials

You can now set passwords for Active Directory, SaaS, and Okta Universal Directory service accounts without triggering target system synchronization. This enhancement simplifies account migration and onboarding workflows while preserving continuous access to connected accounts.

The following releases are now in Preview:

Bulk password rotation for Active Directory accounts (EA)

Admins can now force password rotation for up to 100 Active Directory accounts simultaneously within a project. This enhancement streamlines daily administrative workflows by eliminating the need to rotate individual account passwords manually. See Bulk rotate Active Directory passwords.

Workload access control for secrets

Security admins can now extend least-privilege access controls to machine identities by assigning workload roles to secret policies. This allows workloads to perform operations on secrets while generating individual workload audit logs for tracking.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.08.4: Servicekonto-Passwörter ohne Sync

In der Preview können Passwörter für Active Directory-, SaaS- und Okta-Universal-Directory-Servicekonten gesetzt werden, ohne die Synchronisierung mit dem Zielsystem auszulösen.

Deployment date: August 27, 2026

Release summary

The following releases are now in Preview:

Manual password configuration for resource credentials

You can now set passwords for Active Directory, SaaS, and Okta Universal Directory service accounts without triggering target system synchronization. This enhancement simplifies account migration and onboarding workflows while preserving continuous access to connected accounts.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.08.3: Statisches JWKS und API-Key-Connectors

Admins können JWT Workload Connectors nun mit statischem JWKS-Inhalt konfigurieren und für Workload-Identitäten API-Key-Connectors samt ausgegebenen Secrets erstellen und verwalten.

Deployment date: August 25, 2026

Release summary

The following releases are now in Production:

Static JWKS support for JWT Workload Connectors

Admins operating in private or air-gapped environments can now configure a JWT Workload Connector using static JWKS content. This enables secretless workload authentication for high-security on-premises systems without requiring public key discovery endpoints. See Workloads.

API key authentication for Okta Privileged Access workload identities

Security admins can now create and manage API key connectors and issued secrets for workload identities. This allows legacy and non-OIDC workloads to authenticate securely to Okta Privileged Access. See Workloads.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.08.2: Statisches JWKS und API-Key-Connector

In der Preview unterstützen JWT Workload Connectors statisches JWKS für private oder Air-Gapped-Umgebungen, und Workload-Identitäten können sich per API-Key-Connector bei Okta Privileged Access authentifizieren.

Deployment date: August 20, 2026

Release summary

The following releases are now in Preview:

Static JWKS support for JWT Workload Connectors

Admins operating in private or air-gapped environments can now configure a JWT Workload Connector using static JWKS content. This enables secretless workload authentication for high-security on-premises systems without requiring public key discovery endpoints. See Workloads.

API key authentication for Okta Privileged Access workload identities

Security admins can now create and manage API key connectors and issued secrets for workload identities. This allows legacy and non-OIDC workloads to authenticate securely to Okta Privileged Access. See Workloads.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.08.1: Versionsverlauf und neue Log-Events

Nutzer können jetzt den Versionsverlauf von Zugangsdaten für Secrets sowie Active Directory-, SaaS- und Okta-Universal-Directory-Konten einsehen, und neue System-Log-Events pam.identity_key.create und pam.identity_key.rotate protokollieren Erstellung und Rotation von Team-Identity-Keys.

Deployment date: August 12, 2026

Release summary

The following releases are now in Production:

Credential version history

Okta Privileged Access users can now reveal credential version history for secrets, Active Directory accounts, SaaS app accounts, and Okta Universal Directory accounts. See the Okta Privileged Access user guide.

New System Log events

New System Log events, pam.identity_key.create and pam.identity_key.rotate, are now available for Okta Privileged Access. These events allow admins to audit when per-team identity keys are created and rotated. See the Event Types.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.08.0: Automatische Bereitstellung, Versionsverlauf

In der Preview wird Okta Privileged Access bei aktivem Abonnement automatisch bereitgestellt, und Nutzer können den Versionsverlauf von Zugangsdaten für Secrets und verschiedene Kontotypen einsehen.

Deployment date: August 05, 2026

Release summary

The following releases are now in Preview:

Okta Privileged Access automated app provisioning

Okta Privileged Access is now automatically provisioned in your org when your subscription becomes active. You no longer need to manually add the app from the OIN catalog or configure SCIM provisioning. See Set up Okta Privileged Access.

Credential version history

Okta Privileged Access users can now reveal credential version history for secrets, Active Directory accounts, SaaS app accounts, and Okta Universal Directory accounts. See the Okta Privileged Access user guide.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus dem Text des Eintrags.

Erstmals gesehen am .

Okta Identity Engine von Okta

Okta Identity Engine 2026.09.0: Android 14–17 und Cross App Access

In Okta Identity Engine 2026.09.0 unterstützen Device-Assurance-Richtlinien nun Android 14 bis 17, enhanced dynamic zones kennen neue IP-Service-Kategorien als eigene VPN-Kategorie, und Cross App Access (XAA) steht allen Kunden zur Absicherung des Zugriffs von KI-Agenten und Apps zur Verfügung.

Device assurance OS version update

The following OS versions are now supported in device assurance policies: Android 14, 15, 16, 17 (2026-08-01)

New IP service categories for enhanced dynamic zones

Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

Cross App Access support for AI agents and apps for all customers

Use XAA to secure access between custom SSO-agentic requesting apps and SSO resource apps. XAA enables customers to connect AI agents and apps to take action on behalf of a user, and removes the need for user consent at runtime. The XAA connection is managed by Okta admins, providing them with visibility and control over which actions an AI agent can take on behalf of a user across the supported OIDC and SAML SSO protocols.

  • For the agentic requesting app configuration, see Add AI agents manually, and select your SSO agentic app in User access > App used for access configuration.
  • For the XAA resource app configuration, see Configure resource server connectors. If you're configuring an OIN resource app, it must already have XAA enabled. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.07.2: Secrets verschieben, stabilere Rotation

Nutzer können Secrets nun in einen anderen Ordner verschieben (EA), und SaaS- sowie Okta-Servicekonten bleiben bei fehlgeschlagener Passwortrotation mit dem bestehenden Passwort verfügbar.

Deployment date: July 16, 2026

Release summary

The following releases are now in Production:

Move secret (EA)

Users can now move a secret to a different folder to better align with their team's organizational structure. See Move a secret.

Saas and Okta service accounts available during rotation failures

If the password for SaaS or Okta service accounts fails to rotate, the account status remains Available. This change ensures continued access with the existing password while rotation issues are resolved.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Privileged Access Platform von Okta

Okta Privileged Access Platform 2026.07.1: Automatische Bereitstellung in der Preview

In der Preview wird Okta Privileged Access (PAM) bei aktivem Abonnement automatisch in der Org bereitgestellt, ohne manuelles Hinzufügen aus dem OIN-Katalog oder SCIM-Konfiguration.

Deployment date: July 09, 2026

Release summary

The following releases are now in Preview:

Okta Privileged Access automated app provisioning

Okta Privileged Access (PAM) is now automatically provisioned in your org when your subscription becomes active. You no longer need to manually add the app from the OIN catalog or configure SCIM provisioning. See Set up Okta Privileged Access.

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Okta Classic Engine von Okta

Okta Classic Engine 2026.09.0: Neue IP-Kategorien, JA4-Fingerprints, Agents

Okta Classic Engine 2026.09.0 unterstützt neue IP-Service-Kategorien als einzelne VPN-Service-Kategorie in Enhanced Dynamic Zones, erfasst JA4-TLS-Fingerprints über alle Syslog-Ereignistypen (noch nicht für Orgs mit Custom-Hosted Domains), zeigt den Fortschritt laufender Importe im Import-Monitoring-Dashboard in Echtzeit und bringt den Okta On-Prem MFA Agent 1.8.7 mit Sicherheitsverbesserungen sowie den Radius Agent 2.27 mit internen Verbesserungen und Fehlerbehebungen.

Version: 2026.09.0

New IP service categories for enhanced dynamic zones

Several new IP service categories are now supported as an individual VPN service category in enhanced dynamic zones. See Supported IP categories.

Okta On-Prem MFA agent version 1.8.7

This version includes security enhancements.

Radius Agent version 2.27

This version includes internal improvements and fixes.

JA4 TLS fingerprinting

Okta now captures JA4 TLS client fingerprints across Syslog event types (securityContext.tlsFingerprint.ja4 pr), instead of just a curated subset. This includes telephony events (for example, OTP/SMS delivery) along with sign-in, auth, and token events. This provides customers and Okta's security teams with fingerprint-level visibility to spot bot traffic, toll fraud, and other TLS-based attack patterns that IP/user-agent signals miss on their own.

This is not yet available for orgs on custom-hosted domains.

Enhanced import monitoring with real-time updates

You can now view real-time progress for imports from the Import Monitoring dashboard. This provides greater visibility into the current status of in-progress imports such as the number of data chunks currently being processed.

Copy email from-addresses to the default brand domain …

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Okta Identity Engine von Okta

Okta Identity Engine 2026.09.1: KI-Agenten per CIMD registrieren

Okta Identity Engine 2026.09.1 ermöglicht die Registrierung von KI-Agenten per CIMD mit einer URL statt einer statischen Client-ID, zeigt MCP-Server-Scopes in einem separaten Dialog an und weist in Okta Access Requests offene Manager-Aufgaben und -Fragen bei einem Managerwechsel automatisch dem neuen Manager zu.

CIMD for AI agents

You can now register AI agents with a CIMD so that they can identify themselves with a URL instead of a static client ID. See About Client ID Metadata Documents (CIMD).

UI update for MCP server scopes

Now when you add custom scopes to an MCP server, the list of scopes appears in a separate dialog. See Add an MCP server manually.

Automatic tasks and questions reassignment after a manager change

To prevent access requests from being blocked during organizational changes, Okta Access Requests now automatically reassigns pending manager tasks and manager questions to an employee's new manager whenever a manager change occurs. This automated reassignment ensures that approvals proceed without manual IT intervention or delays, even if the previous manager's account has already been deactivated. This is available for requests built with both request conditions and request types.

Requester timeline view …

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Okta Identity Engine von Okta

Okta Identity Engine 2026.09.2: Eindeutige MCP-Namen, Sign-In Widget 7.49.1

Okta Identity Engine 2026.09.2 verlangt eindeutige Anzeigenamen für MCP-Server, wählt bei Okta FastPass in Authentifizierungsketten standardmäßig „Phishing resistant“ aus, bringt das Sign-In Widget 7.49.1, konfigurierbare Begründungen für Entscheidungen bei Access Requests sowie Provisioning für Kong AI.

Unique MCP server names

When you register an MCP server, it must now have a unique display name. 

Sign-In Widget, version 7.49.1

For details about this release, see Sign-In Widget Release Notes. For more information about the widget, see Okta Sign-In Widget.

Automatic phishing resistance for FastPass in authentication chains

When you include Okta FastPass in an authentication method chain, the Phishing resistant characteristic is now selected by default. 

Access Requests decision justification

Okta Identity Governance now supports configurable justification controls for access request decisions, providing requesters more transparency into their approvals and denials. Admins can configure the approval sequence or request type settings to include the decision justification field for approval tasks, allowing approvers the option to provide a rationale for their decision. All submitted justification text is captured on the request ticket and made available to the requester, providing insight into access decisions. See Request type settings.

Provisioning for Kong AI

Provisioning is now available for the Kong AI integration. See Integrate Kong AI with Okta.

Editable resource URL for MCP servers …

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Okta Identity Governance von Okta

Okta Identity Governance 2026.09.2: Begründungen bei Access Requests

Okta Identity Governance unterstützt jetzt konfigurierbare Begründungsfelder für Entscheidungen bei Access Requests, sodass Genehmiger ihre Entscheidung begründen können und Antragsteller diese Begründung einsehen, und behebt zudem Fehler bei Slack-Benachrichtigungen zu Kampagnen.

Features and Enhancements

Access Requests decision justification

Okta Identity Governance now supports configurable justification controls for access request decisions, providing requesters more transparency into their approvals and denials. Admins can configure the approval sequence or request type settings to include the decision justification field for approval tasks, allowing approvers the option to provide a rationale for their decision. All submitted justification text is captured on the request ticket and made available to the requester, providing insight into access decisions. See Configure an approval sequence and Request type settings.

Fixes

  • Warnings and errors weren't propagated to Slack for campaigns in the STAGING_FAILED state. (OKTA-1272033)

  • On rare occasions, the start date of a staged campaign was blank in Slack when staging started shortly after the campaign was eligible. (OKTA-1273337)

Previous releases

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Okta Identity Governance von Okta

Okta Identity Governance 2026.09.1: Kampagnen-Staging und Status-Zeitleiste

Zertifizierungskampagnen lassen sich vor dem Start als Early-Access-Funktion stufenweise vorbereiten (Staging), und Antragsteller sehen in der Okta Access Request app eine Status-Zeitleiste ihrer Aufgaben.

Features and Enhancements

Stage certification campaigns before launch

Staging a campaign lets you preview target users, resources, and reviewer assignments in advance to ensure accurate scope, fix configuration errors, and guarantee that requests reach the correct reviewers from day one. See Stage a campaign.

This is an Early Access release. See Enable self-service features.

Requester timeline view

Requesters can now view a detailed status timeline of their request's tasks directly from the Okta Access Request app. This enhanced visibility allows requesters to easily track the progress of their requests, see who has approved individual tasks, and identify remaining tasks, helping users stay informed throughout the approval process and reducing unnecessary status inquiries. The timeline is available for requests built with access request conditions.

Automatic tasks and questions reassignment after a manager change …

Originalquelle(öffnet in neuem Tab)Problem melden