Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Okta Workforce Identity Cloud November 2024 Updates

Okta
07/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


We will go over new generally available features and early access new features. Let's get started. Generally available features. Improved user experience for group member counts. Groups now use async counts to determine user membership for groups that exceed 10,000 users. This improves the performance of both the groups page and the group selector on the sign-on policy page. Give access to Okta support. Admins can now control how members of the Okta support team can access their org. To support this, the account page provides the following two options. Impersonation grants for cases, which allows the Okta support team to sign into your org as a read-only admin to troubleshoot issues. And support user grants for self-assigned cases. This allows an Okta support representative to access your org settings after they've opened a case. Using these settings, admins can select the right level of support access for their org. YubiKey pre-registration. Customer admins were previously unable to enroll and ship YubiKeys as WebAuthn enrollments in a quick and automated way. The YubiKey pre-reregistration feature enables admins to pre-register YubiKey factors as WebAuthn enrollments for both staged and existing users using a SAE, workflows, and Yubico integration to seamlessly handle the registration and shipment. Seamless ISV experience for SCIM. Okta now provides a seamless ISV experience to optimize the Okta Integration Network submission experience for SCIM integrations. This new experience enables independent software vendors to build and manually test their SCIM integration metadata before submission to the OIN. This reduces the time needed for the OIN team to review and validate that the SCIM integration functions as intended, which shortens the time to publish in the OIN. This experience also incorporates communication processes in Salesforce, enabling improved collaboration internally within Okta teams and externally with independent software vendors. Benefits include less tools for technology integrators to navigate to and use, quicker time to submit SSO and SCIM OIN integration due to testing and validation of integration metadata during submission process, and quicker time to publish due to reduction in OIN operations responsibilities to manually add metadata. Multiple Identifiers. Today, end users must sign in to Okta with a username or email address only. With the Multiple Identifiers feature, admins can configure identifiers or user attributes from Universal Directory that an end user can enter to authenticate. Multiplier Identifiers work in sign-on, recovery, self-service registration, and unlock flows. Admins can configure up to three identifiers, including email, which is still a required identifier. Benefits include users can use alternate identifiers across sign-in, recovery, unlock flows in Okta. Admins can configure identifiers on a per-application basis and supports unique custom user profile attributes only. Allow or Disallow an Authenticator Instance in an Authentication Policy Rule. You can now specify a custom authenticator instance in the Allow or Disallow lists of an Authentication Policy Rule. This provides more granular control over which authenticators are available to users. Let's wrap up with a look at Early Access Features. IP Exempt Zone. Use this feature to always allow traffic from specific gateway IPs irrespective of any Okta Threat Insight configurations or network zones that are configured. As Block Lists. OpenID Connect Identity Providers now support Full Group Sync and adding a user to a group that they don't already belong to. A user who authenticates with an external IDP is added to all available groups when Full Sync of Groups is enabled. The user is added to any groups that they don't already belong to when Add User to Missing Groups is enabled. This allows you to specify certain groups that users should be added to. Create Dynamic Resource Sets with Conditions. Resource Set conditions help you limit the scope of a role by excluding an admin's access to certain apps. This gives you more granular control over your custom admin roles and helps meet your org's unique security needs. Benefits include allowing customers to reserve access to sensitive resources to a small subset of admins and reduces time spent adding individual resources to resource sets. Seamless and Secure Authentication with Paskey Autofill. Paskeys offer a streamlined sign-in experience to users by leveraging their browser's existing autofill capabilities. This allows users to quickly and intuitively sign in to an org without typing their credentials or seeing extra prompts. This secure, phishing-resistant solution works seamlessly across devices, delivering both enhanced security and convenience for modern authentication needs. Secure Partner Access provides a secure way for external business partners to access your org's resources. It streamlines your partner management tasks, reduces IT workload, and simplifies the process of configuring your org's security requirements. Benefits include centralized user management, visibility, and control of all your business partners within a single Okta tenant using Okta Realms. Extend strong security controls like device assurance and passwordless authentication to protect partner access and delegate user management and app assignments to optimize IT operations. Thanks for viewing the release highlights for Okta's Workforce Identity Cloud. For additional details, please visit the Okta release notes and help article links which can be found in the video description.

TL;DR

  • Okta's November 2024 Workforce Identity Cloud release delivers performance improvements for large-scale group management and introduces granular admin controls for Okta Support access levels.
  • New YubiKey pre-registration workflows enable automated WebAuthn enrollment and shipment, while the streamlined SCIM ISV submission process reduces Okta Integration Network publishing timelines.
  • Multiple Identifiers feature allows users to authenticate with custom attributes beyond email, with per-application configuration and support across sign-on, recovery, and unlock flows.
  • Early access features preview IP Exempt Zones, enhanced group sync for OpenID Connect IDPs, dynamic resource sets with conditions, passkey autofill, and Secure Partner Access for external user management.

Generally Available Features

Okta's November 2024 release introduces several production-ready enhancements to the Workforce Identity Cloud platform. Key improvements include async group member counting for organizations with over 10,000 users, significantly improving performance on groups and sign-on policy pages. Administrators gain new granular control over Okta Support access through impersonation grants and support user grants, allowing organizations to balance troubleshooting needs with security requirements. The release also delivers YubiKey pre-registration capabilities, enabling automated WebAuthn enrollment and shipment workflows through integration with Yubico. Additional features include a streamlined SCIM integration submission process for ISVs through the Okta Integration Network, reducing time-to-publish through automated testing and validation.

Authentication and Access Control Enhancements

The Multiple Identifiers feature expands sign-in flexibility by allowing administrators to configure up to three user attributes from Universal Directory as authentication identifiers, moving beyond the traditional username-or-email limitation. This capability extends across sign-on, recovery, self-service registration, and unlock flows, with per-application configuration support. Authentication policy rules now support instance-level authenticator control through allow and disallow lists, providing more precise governance over which specific authenticator instances users can leverage. Early access features preview upcoming capabilities including IP Exempt Zones for always-allow traffic rules, enhanced OpenID Connect IDP group synchronization, dynamic resource sets with conditional exclusions for custom admin roles, passkey autofill for streamlined authentication, and Secure Partner Access for centralized external partner management through Okta Realms.

Chapters

0:00 - Introduction
0:11 - Generally Available Features
1:02 - YubiKey Pre-Registration
2:29 - Multiple Identifiers
3:31 - Early Access Features
5:54 - Closing

Key Quotes

0:16 "Groups now use async counts to determine user membership for groups that exceed 10,000 users."
0:34 "Admins can now control how members of the Okta support team can access their org."
2:36 "With the Multiple Identifiers feature, admins can configure identifiers or user attributes from Universal Directory that an end user can enter to authenticate."
4:54 "This allows users to quickly and intuitively sign in to an org without typing their credentials or seeing extra prompts."

FAQ

What level of access does Okta Support receive when using the new support access controls?

Administrators can choose between two access levels: Impersonation grants for cases provide read-only admin access for troubleshooting, while support user grants for self-assigned cases allow Okta representatives to access org settings after opening a support case. Both options give admins control over the scope of support team access.

How does the Multiple Identifiers feature work with existing authentication flows?

Multiple Identifiers allows admins to configure up to three user attributes from Universal Directory as authentication identifiers, including email which remains required. Users can authenticate with any configured identifier across sign-in, recovery, self-service registration, and unlock flows. Configuration is available on a per-application basis and supports unique custom user profile attributes only.


Categories:
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Product Updates
  • Technical Deep Dive
  • Authentication
  • Admin Tools
  • Identity and Access Management
  • Multi-Factor Authentication
  • WebAuthn
  • SCIM Provisioning
  • Authentication Policies
  • Admin Role Management
  • Passwordless Authentication
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Okta Workforce Identity Cloud November 2024 Updates

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/21/2026
                        04:00 AM
                        07/21/2026
                        Strategies for Managing AI Governance: Safeguarding App-to-LLM API Traffic
                        https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-safeguarding-app-to-llm-api-traffic/
                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version