<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Update Office 365 to Support Application-Based Authentication for Okta Provisioning

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

Okta continuously improves integrations to deliver the highest standards of security and reliability. In alignment with Microsoft's transition, Okta is proactively modernizing its Office 365 provisioning architecture. This involves upgrading the integration from the legacy service account model to a secure, advanced Application-Based Authentication (ABA) model.

Re-authentication must be completed ahead of Microsoft's enforcement deadline of September 30, 2026. After this date, provisioning will stop for any tenants that have not re-authenticated.

Applies To

  • Okta Identity Engine (OIE) and Okta Classic Engine
  • Customers using the Office 365 or Office 365 GCC High app for Provisioning (user sync or universal sync) using either MSol or MS Graph.

  • Only apps configured before this feature's release in the august monthly as the new architecture is by default.

What Prerequisites Are Required Before Updating Office 365 Provisioning?

An Office 365 application with provisioning enabled, an Okta App Administrator role, and a Microsoft Global Administrator credential with multifactor authentication (MFA) enabled are required before updating an Office 365 application to support Application-Based Authentication.

  • An Office 365 application with provisioning currently enabled.
  • An Okta App Administrator role in Okta to configure Office 365 provisioning.
  • A Microsoft Global Administrator credential with MFA enabled to update the provisioning settings in Okta.

What Changes with Application-Based Authentication and Why Does It Matter?

Okta is modernizing the Office 365 integration by moving to a resilient Application-Based Authentication (ABA) framework. This update introduces two components that become visible in the Microsoft environment: the Application Registration, which serves as the configuration blueprint, and the Service Principal, which serves as the enterprise identity that executes the provisioning operations.

 

During the authentication process, administrators grant consent to a set of permissions that includes two new permissions, Application.ReadWrite.All and AppRoleAssignment.ReadWrite.All. Okta uses both permissions strictly for provisioning, as detailed in the Permissions Reference Documentation.

 

Administrators can begin re-authenticating ahead of Microsoft's enforcement deadline of September 30, 2026, after which Okta stops provisioning for tenants that have not re-authenticated.

How Does an Administrator Update Office 365 to Support Application-Based Authentication?

An administrator locates the Office 365 application in the Admin Console, opens the provisioning integration settings, initiates re-authentication, and grants the new permissions when prompted, by following these steps:

  1. In the Admin Console, navigate to Applications.
  2. Select the Office 365 application.
  3. Select the Provisioning tab, then choose Integration from the left-hand settings menu.
  4. Select Edit.
  5. Select Re-Authentication, then grant the permissions when prompted.
  6. Select Save.

NOTE:

For Preview orgs, re-authentication is required after the July 13th, 2026 release to enable the update, although the new permission prompts may appear a few days early. 

 

For Production orgs, re-authentication is required after the August 14th, 2026 release to enable the update, although the new permission prompts may appear as early as July.

Related References

 

Loading
Okta Support - Update Office 365 to Support Application-Based Authentication for Okta Provisioning