Classic Engine Feature EOL: SSR, Desktop SSO, Device Trust

Starting March 5, 2027, Okta ends support for a few capabilities on Classic Engine. Identity and security requirements continue to evolve. Organizations expect authentication experiences that are more secure, flexible, and adaptable to changing users, devices, and applications. Okta invests in Okta Identity Engine, the modern foundation for passwordless authentication, device assurance, phishing-resistant multifactor authentication, and adaptive security policies.
By moving to Okta Identity Engine, you access an environment aligned with modern security practices that is stronger, more capable, and built to support how you protect access.
What’s changing in Okta Classic Engine
Here’s the full list of affected capabilities:
- Self-Service Registration
- Desktop Single Sign-On (Integrated Windows Authentication, or IWA)
- Device Trust
Once support ends, Okta turns off these capabilities on Classic Engine, and you lose access to them unless you upgrade to Okta Identity Engine first. Okta no longer addresses bugs, security vulnerabilities, or broken flows associated with them after that date. Each capability moves to a modern, more secure approach within Identity Engine, where it continues to benefit from ongoing innovation.
Why upgrade to Okta Identity Engine
Identity Engine gives you authentication capabilities Classic Engine doesn’t have, including passwordless authentication, device assurance, and a modernized policy framework built on a newer authentication pipeline. The upgrade itself is free, you get all these capabilities at no additional licensing cost as part of your existing Okta subscription.
Identity Engine accelerates five core use cases:
- Passwordless: Remove password from the sign-in flow entirely, instead of layering a second factor on top of it
- Phishing-resistant: Close every route to the account, not just the front door. An account is only as phishing-resistant as its weakest enrollment and recovery path.
- ID verification : Confirm that employees and customers are who they claim to be before you issue a credential or reset one
- Zero trust: Identity and access management that goes beyond what NIST Authenticator Assurance Level (AAL) guidelines recommends
- Device assurance: Fine-grained controls that check device posture as a condition of access
Okta Identity Engine elevates identity capabilities
Self-Service Registration allows end users to create their own accounts without administrator involvement. In Identity Engine, you use the Profile Enrollment Policy, which provides the same user self-service experience while enhancing security and modern account management.
Desktop Single Sign-On (SSO), specifically IWA, provides silent desktop authentication through on-premises infrastructure. Migrate to Agentless Desktop Single Sign-On (ADSSO) for modern desktop authentication without agents, or to Okta FastPass for passwordless platform authentication. Consult your Okta account team to determine which option fits your authentication and device management strategy.
Device Trust restricts app access to managed devices through Workspace ONE. In Identity Engine, migrate to management attestation with Okta Verify instead, which verifies that Okta Verify manages and trusts the mobile device before allowing access, providing enhanced device assurance beyond the previous Device Trust feature.
For step-by-step guidance on replacing these Classic Engine auth flows, see Replace Classic Engine authentication flows with Okta Identity Engine.
Planning your migration to Okta Identity Engine
Every organization’s environment differs, so your timeline and steps depend on your current configuration and feature usage. Reach out to your account executive for help and clarification on scheduling your upgrade.
Key timeline for Classic Engine capabilities sunsetting
Self-Service Registration, Desktop SSO (IWA), and Mobile Device Trust sunset on Classic Engine according to the timeline below.
| Milestone | Date(s) |
|---|---|
| Initial notice | August 5, 2026 |
| Reminders | September 7, October 7, and November 9, 2026; January 11, February 15, and March 1, 2027 |
| End of support | March 5, 2027 |
Mark your calendar: March 5, 2027, is the hard deadline. Upgrade before then to avoid losing access to Self-Service Registration, Desktop SSO (IWA), and Device Trust on Classic Engine.
Best practices after your Okta Identity Engine upgrade
Not every Classic Engine feature carries over to Identity Engine. Identity Engine fully supports most features, and in most cases, a comparable feature is available. Your Okta field and upgrade teams tell you which features are unsupported and provide steps to migrate to the replacement feature.
If you have questions about any part of this transition, contact Okta Support or your account team.
Plan your migration now!
Schedule testing in a non-production environment before planning your production upgrade during an appropriate maintenance window. Contact Okta Support or your account team with any questions. You have until March 5, 2027, to complete your upgrade, so start your assessment now to make sure you land on the best upgrade window for your organization.
Resources to aid your Okta Identity Engine migration
If you’d like to learn more about identity and the concepts covered in this post, explore these official Okta resources:
- Introducing Okta Journeys: A Better Way for Developers to Learn Identity
- Replace Classic Engine authentication flows with Okta Identity Engine
- It’s Time to Evolve Authentication Security
Remember to follow us on LinkedIn and subscribe to our YouTube for more exciting content. Let us know how your Identity Engine upgrade goes in the comments below, we’d love to hear about it.
Okta Developer Blog Comment Policy
We welcome relevant and respectful comments. Off-topic comments may be removed.