Skip to content
TrustList
News

Okta to switch off three Classic Engine features on 5 March 2027

Editorial

By TrustList Editorial

Okta will switch off Self-Service Registration, Desktop SSO (IWA) and Device Trust on Classic Engine on 5 March 2027. Tenants still on Classic Engine need to upgrade to Identity Engine, which Okta says is free, before then.

About Okta to switch off three Classic Engine features on 5 March 2027

Okta to switch off three Classic Engine features on 5 March 2027

22 September 2026 — Okta said in a developer blog post dated 18 September 2026 that three capabilities on its older Classic Engine will reach end of support on 5 March 2027: Self-Service Registration, Desktop Single Sign-On using Integrated Windows Authentication (IWA), and Device Trust. After that date Okta will turn the features off on Classic Engine and stop fixing bugs, security vulnerabilities or broken flows in them. The post says customers were first notified on 5 August 2026, with reminders on 7 September, 7 October and 9 November 2026, and on 11 January, 15 February and 1 March 2027.

Not yet independently verified. This rests on Okta's own developer blog post. We found no independent coverage and no matching entry in Okta's help-centre release notes, so the dates and scope are Okta's own statement only. We will update this when it can be confirmed, and remove this note.

What changes

Each feature has a named replacement in Okta Identity Engine:

  • Self-Service Registration moves to the Profile Enrollment Policy.
  • Desktop SSO (IWA), which relies on on-premises infrastructure, moves to Agentless Desktop Single Sign-On or to Okta FastPass. Okta asks customers to consult their account team on which suits them.
  • Device Trust, which the post describes as restricting app access to devices managed through Workspace ONE, moves to management attestation with Okta Verify.

Okta says the upgrade to Identity Engine is free and included in existing subscriptions. It also says not every Classic Engine feature carries over, and that its field and upgrade teams will tell each customer which features are unsupported and how to migrate. Organisations that have not upgraded lose access to the three features when support ends. For step-by-step help, the post points to Okta's developer guide on replacing Classic Engine authentication flows with Identity Engine, and to account executives for help scheduling the upgrade.

What to do

  • Confirm which engine you run. If your tenant is still on Classic Engine, check whether any of the three features is in use, including customer-facing registration flows and sign-in on Windows desktops.
  • Book the upgrade. Ask your Okta account team for an upgrade window well before 5 March 2027, and test in a non-production environment first, as Okta recommends.
  • Plan desktop sign-in separately. A change to how Windows desktops sign in can affect many staff at once, so involve your Windows and device management owners early.
  • Check device access rules. The post says "Device Trust" in most places and "Mobile Device Trust" in its timeline; ask Okta exactly which Device Trust configurations fall under the deadline.
  • Update your supplier register with the date, and ask any partner that manages your Okta tenant how it will handle the move.

What the post leaves out

The post does not say whether Classic Engine as a whole has an end date, how many customers still use it, or whether any extension will be offered for the three features.

Sources