Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Okta January 2025 Release: New Identity Features

Okta
06/28/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Welcome to the monthly release highlights for Okta's Workforce Identity Cloud. We'll go over new generally available features and early access new features. Let's get started. Generally available features. Multiple identifiers. Enhancements to the profile enrollment policy. Allow configuration of identifiers that can be leveraged for Okta's sign-in flows using custom profile attributes. Today, end-users must sign in to Okta with a username or email address only. With the multiple identifiers feature, admins can configure identifiers or user attributes from Universal Directory that an end-user can enter to authenticate. Multiple identifiers work in sign-on, recovery, self-service registration, and unlock flows. Admins can configure up to three identifiers, including email, which is still a required identifier. With multiple identifiers, admins can streamline the sign-in experience by giving users more options to identify themselves with. Admins can also specify which identifiers can be used across various applications. OAuth 2.0 security for invoking API endpoints. Okta Workflows users can now securely invoke API endpoints using OAuth 2.0 protocols and their Okta org authorization server. Compared with the existing token authorization option, this feature is more secure while also being easier to implement. Add the Okta Workflows Invoke Managed Scope to any new or existing app integration to make it eligible to invoke your API endpoint. Just-in-time local account creation for macOS. Just-in-time local account creation is available for Okta device access. Okta admins can allow macOS users to create a local account by entering their Okta username and Okta password in the macOS sign-in dialog. This feature enables easier account management for admins and streamlines the user account creation process for end-users. This is especially beneficial for devices or workstations that support multiple users. Identity verification with third-party identity verification providers. When users take certain actions, identity verification enables you to use a third-party identity verification provider to verify the identity of your users. Verification requirements and the identity verification provider are based on your authentication policies and configurations within your Okta org. Okta supports Persona as a third-party identity verification provider. Benefits include reducing social engineering attacks using document and liveness verification and enhancing protection and trust across onboarding, authentication, account recovery, and help desk support. Block syncable passkeys. You can now block syncable passkeys during authentication. Previously, you could only block them during enrollment. This enhances the security of your org by preventing users from presenting such passkeys to attempt to enroll new, unmanaged devices. Authentication method chain. With this feature, you can require users to verify with multiple authentication methods in a specified sequence. You can create multiple authentication method chains in an authentication policy rule to cater to different use cases and scenarios. This feature is now also supported in the Okta account management policy. Additional use case selection in the OIN wizard. Independent software vendors can select the following additional use case categories when they submit their integration to the OIN. Automation, centralized logging, directory and HR sync, and multi-factor authentication. Let's wrap up with a look at early access features. Multi-factor authentication for secure partner access admin portal. MFA is required for accessing the partner admin portal app. Entitlement claims. You can now enrich tokens with app entitlements that produce deeper integrations. After you configure this feature for your app integrations, use the Okta expression language and identity engine to add entitlements at runtime as OIDC claims and SAML assertions. Thanks for viewing the release highlights for Okta's Workforce Identity Cloud. For additional details, please visit the Okta release notes and help article links which can be found in the video description.

TL;DR

  • Multiple identifier support now allows users to authenticate with custom profile attributes from Universal Directory, not just username or email, streamlining sign-in across authentication, recovery, and self-service registration flows.
  • Security enhancements include OAuth 2.0 for Workflows API endpoints, third-party identity verification with Persona for document and liveness checks, and the ability to block syncable passkeys during authentication to prevent unmanaged device enrollment.
  • Operational improvements feature just-in-time local account creation for macOS users, authentication method chaining for sequential multi-factor verification, and expanded OIN wizard categories including automation, centralized logging, and directory sync use cases.

Summary

This monthly release overview covers Okta's January 2025 platform updates for Workforce Identity Cloud, highlighting both generally available and early access features. The release introduces significant enhancements to authentication flexibility, including multiple identifier support that allows users to sign in with custom profile attributes beyond traditional username or email. Security improvements include OAuth 2.0 protocols for Workflows API endpoints, third-party identity verification integration with Persona, and enhanced passkey management with the ability to block syncable passkeys during authentication. The update also addresses operational efficiency with just-in-time local account creation for macOS devices, authentication method chaining for multi-step verification requirements, and expanded use case categories in the Okta Integration Network wizard. Early access features preview upcoming capabilities around multi-factor authentication for partner portals and entitlement claims for deeper application integrations using Okta Expression Language.

Chapters

0:00 - Introduction
0:10 - Multiple Identifiers
1:17 - OAuth 2.0 Security
1:41 - macOS Account Creation
2:13 - Identity Verification
2:56 - Passkeys & Authentication
3:50 - Early Access Features

Key Quotes

0:30 "Today, end-users must sign in to Okta with a username or email address only. With the multiple identifiers feature, admins can configure identifiers or user attributes from Universal Directory that an end-user can enter to authenticate."
1:17 "Okta Workflows users can now securely invoke API endpoints using OAuth 2.0 protocols and their Okta org authorization server. Compared with the existing token authorization option, this feature is more secure while also being easier to implement."
2:44 "Benefits include reducing social engineering attacks using document and liveness verification and enhancing protection and trust across onboarding, authentication, account recovery, and help desk support."

FAQ

What authentication methods can users now use with multiple identifiers?

Admins can configure up to three identifiers including email (which remains required) using custom profile attributes from Universal Directory. These identifiers work across sign-on, recovery, self-service registration, and unlock flows, and can be specified per application.

How does the new OAuth 2.0 security for Workflows improve upon existing token authorization?

OAuth 2.0 protocols using the Okta org authorization server provide more secure authentication while being easier to implement. Admins simply add the Okta Workflows Invoke Managed Scope to any app integration to enable secure API endpoint invocation.


Categories:
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Product Update
  • Technical Deep Dive
  • Authentication
  • Security Operations
  • Identity and Access Management
  • Multi-Factor Authentication
  • Authentication Policies
  • Passkey Management
  • Identity Verification
  • OAuth 2.0 Security
  • Workflow Automation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Okta January 2025 Release: New Identity Features

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    13

                    Innovative Security Solutions with Netskope & Omada in Enterprise AI

                    08/13/202612:00 PM ET
                    • Aug
                      27

                      Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                      08/27/202601:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 08/13/2026
                        12:00 PM
                        08/13/2026
                        Innovative Security Solutions with Netskope & Omada in Enterprise AI
                        https://www.truthinit.com/index.php/channel/2065/innovative-security-solutions-with-netskope-omada-in-enterprise-ai/
                      • 08/27/2026
                        01:00 PM
                        08/27/2026
                        Becoming Agent Ready with Cyera: Essential Strategies and Insights
                        https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                      • 08/27/2026
                        01:00 PM
                        08/27/2026
                        Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                        https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/03/2026
                        01:00 PM
                        09/03/2026
                        Verge.io: Can You Afford Your Next Storage Refresh?
                        https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      • 11/19/2026
                        01:00 PM
                        11/19/2026
                        360View: Govern, Secure & Recover Your Microsoft 365 Environment
                        https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version