LICENSEWARE

Okta Workforce Identity licensing

This article covers how Okta counts users for its Workforce Identity suites and individual products (Single Sign-On, Universal Directory, MFA, Lifecycle Management, Identity Governance, Workflows, Identity Threat Protection and others). For the contract and the other product families, see Okta licensing.

On This Page

Okta Workforce Identity licensing covers the Okta products a company uses to sign in, provision and govern its own employees, contractors and other workforce users. The Product Subscription Reference Guide (PSRG) says these products “are for use solely with Okta Workforce Identity Users”. A Workforce Identity User is an individual who uses the service to reach workforce applications such as human resources, productivity and custom-built workforce applications.[1] Whether a User qualifies as a Workforce Identity User “is at Okta’s sole and reasonable discretion”.[1] Okta sells Workforce Identity “as suites on a per-user, per-month basis” billed annually, and most products can also be bought on their own or added to a suite.[2] Users of customer-facing applications fall under Okta Customer Identity or Auth0 instead; see Okta Customer Identity and Auth0 licensing.

Editions

The PSRG lists six Workforce Identity Suites: Starter, Starter with Adaptive MFA, Core Essentials, Essentials, Professional and Enterprise. It also lists combined Professional and Enterprise Suites that include Okta Customer Identity B2C or B2B.[1] The suites are pre-packaged sets of products, “currently only available to new customers”, and must be bought “as a complete Suite rather than as individual components”.[1] Catalog: Suites are sold whole and only to new customers.

Suite List price (per user per month) Components named by Okta 
Starter USD 6[2] Universal Directory, Single Sign-On, MFA, Workflows (5 flows)[1] 
Core Essentials USD 14[2] Offered as a lower-priced alternative to Essentials[2] 
Essentials USD 17[2] Starter components with Adaptive MFA, plus Lifecycle Management, Access Governance, Workflows (50, 150 or Maximum flows) and Okta Privileged Access with 1 Resource Unit[1] 
Professional On request[2] Essentials plus Device Access, Identity Threat Protection, ISPM (may be limited to 2 or 5 integrations), Maximum flows, Preview Sandbox and 0.5 Resource Units per user[1] 
Enterprise On request[2] Professional plus API Access Management, Okta Access Gateway, ISPM (50 integrations) and 100,000 Machine to Machine Tokens per year[1] 

The PSRG’s entry for Core Essentials repeats the component list of Starter with Adaptive MFA, and the pricing page does not itemise it. A buyer should therefore confirm its contents on the Order Form. Products that are already part of a suite “cannot also be purchased alongside that Suite, except in limited circumstances”.[1]

Okta sometimes renames workforce SKUs. Older Order Forms may show names such as “IT Products - Lifecycle Management, 5 OIN Apps”, which became “IT Products - Lifecycle Management” in 2019. “Unlimited Workforce Identity Workflows” became “Workforce Identity Workflows (Maximum flows)” on 2026-05-14.[5] Catalog: Renamed products appear under new names on Order Forms.

Metrics

All Workforce Identity products use the Workforce Identity User as their unit. The MSA defines Users as “individuals (including non-human devices, such as applications or services)” who are authorised by the customer and for whom a subscription has been procured.[3] The PSRG makes the count concrete. Every User must have at least one subscription allocated, corresponding to a User ID in the Okta org.[1] Some products add secondary limits measured in other units: flows for Workflows (Active workflow), integrations for Identity Security Posture Management (ISPM Integration) and tokens for machine-to-machine API access (M2M Token).

Counting / floors

The Active Status rule

Okta “determines subscription compliance based on the count of User IDs” that have any of five statuses in Universal Directory: Active, Recovery, Locked-Out, Password Expired or Suspended.[1] Suspended and locked-out users therefore still consume a subscription, and a user stops counting only when deactivated. Each User ID is counted separately. This applies to non-human User IDs such as service accounts, to people who need more than one user type, and to Users assigned to several non-sandbox orgs, who need a separate User ID in each org.[1] The PSRG’s example is a teacher who enrols as a student at her own college. She needs a second profile with a Student user type and “a corresponding second subscription”.[1] Catalog: Compliance is measured by User IDs in an Active Status; Each User ID and each org is counted separately.

Product activation rules

Each product has its own activation rule, and the counts can differ inside one org.

Product Activation (what is counted) 
Universal Directory Users in an Active Status in the org[1] 
Single Sign-On Users in an Active Status with at least one application assigned; self-assigned personal applications do not count[1] 
Single Sign-On (5 or 10 app limit) As above, with up to 5 or 10 applications per User; the limit is per User, not per org[1] 
MFA and Adaptive MFA Users in an Active Status enrolled in an included factor (Okta Verify Push, SMS, Voice, YubiKey, WebAuthn, U2F, Custom OTP, Smart Card)[1] 
Device Access Users assigned to the Desktop MFA or Platform Single Sign-On for macOS application, or to an application whose sign-on policy uses an Advanced Posture Check[1] 
API Access Management Users assigned to OIDC applications with OAuth authorization provided by Okta[1] 
Okta Access Gateway Users assigned to active Access Gateway applications; no limit on applications[1] 
Lifecycle Management Users assigned to OIN applications with provisioning enabled, or all Users in an org where Lifecycle Management features (access request workflows, self-service registration, Org2Org) are enabled[1] 
Workforce Identity Workflows All Users in an org with at least one active workflow[1] 
Access Governance (Okta Identity Governance) All Users in an org where Access Governance features are enabled[1] 
Identity Threat Protection All Users in an org where Identity Threat Protection features are enabled[1] 
Identity Security Posture Management User IDs in the customer’s identity provider(s); each Active User in an integrated Okta org activates a subscription[1] 

Two patterns stand out. First, assignment-based products (Single Sign-On, API Access Management, Access Gateway, Device Access) count only users with a qualifying assignment or enrolment. Second, org-wide products (Lifecycle Management once its features are enabled, Workflows, Access Governance, Identity Threat Protection) count every Active User in the org as soon as a single feature is turned on. Catalog: Single Sign-On counts Users with at least one assigned application; Lifecycle Management can activate every User in the org.

Matching quantities and prerequisites

Several products must be bought in the same quantity as Universal Directory. For Workforce Identity Workflows, “The number of subscriptions purchased for Workforce Identity Workflows must match the number of subscriptions purchased for Universal Directory”.[1] The same matching rule applies to Okta Identity Governance and to Identity Threat Protection.[1] Workflows and Identity Governance customers must also buy a Single Sign-On licence for every Workflows administrator, with at least one Single Sign-On licence in total.[1] Catalog: Workflows, Identity Governance and Identity Threat Protection must match Universal Directory.

Other prerequisites:

  • API Access Management and Okta Access Gateway require Single Sign-On.[1]
  • Device Access requires MFA, Adaptive MFA or Single Sign-On. Advanced Posture Checks also need Adaptive MFA.[1]
  • Lifecycle Management requires Universal Directory.[1]
  • Identity Threat Protection requires Universal Directory, Single Sign-On and Adaptive MFA.[1]
  • MFA and Adaptive MFA cannot be bought together. Neither includes the telephony that delivers SMS and Voice factors, so customers must configure an external telephony provider.[1] Catalog: MFA counts enrolled Users; telephony is not included.

Limits on flows and integrations

Workflows SKUs cap the number of active flows per org. Starter includes 5 flows, Essentials 50 (or 150 or Maximum as ordered), and Professional and Enterprise Maximum flows.[1] Customers of both Okta and Auth0 may extend up to five active workflows to Auth0. These count toward the flow limit but do not activate additional Workflows users.[1] Identity Security Posture Management allows up to 50 ISPM Integrations, or 2 or 5 on the limited SKUs. The 2-integration version is sold only within suites and covers one Okta org plus one of AWS, Azure Active Directory or Salesforce.[1]

Floors and growth

Okta Workforce Identity carries a “$1,500 annual contract minimum”.[2] For suites, Okta says that “all products share the same number of subscriptions”. Adding users for one product only is therefore not normally possible, except for Workflows, Okta Privileged Access and Machine-to-Machine tokens.[2] Catalog: Okta Workforce Identity has a USD 1,500 annual minimum; Extra licences are added to the whole suite.

A worked example

Take an org with 1,000 employees on Single Sign-On and Universal Directory, 40 service-account User IDs, 25 suspended leavers who have not been deactivated, and 30 contractors with no application assigned. Universal Directory counts every Active Status User ID: 1,000 + 40 + 25 + 30 = 1,095. Single Sign-On counts only those with an assigned application, which may be close to 1,000. If an administrator then activates a single workflow, Workforce Identity Workflows also counts all 1,095, and its quantity must match Universal Directory. The cheapest fix is usually administrative: deactivate leavers, review service accounts, and decide deliberately before switching on org-wide features. See true-up.

Virtualization & partitioning

Workforce Identity products are cloud services with no processor or virtualization rules. Separate orgs are the only partitioning that matters. A User assigned to several production orgs is counted in each, while sandbox orgs are excluded from the multi-org rule.[1] Multi-Org Deployment, which lets developers create orgs through the Org Creation API, is counted per Active org.[1]

Cloud / BYOL

Not applicable. Okta hosts the service. Machine-to-machine API traffic is licensed separately. The Machine-to-Machine Tokens SKU counts access tokens issued with the OAuth Client Credentials grant during each subscription year, and the Enterprise Suite includes 100,000 a year.[1]

Programs

Out of scope

  • Legacy Workforce SKUs listed in the separate Okta Legacy SKUs reference guide.
  • Prices for Professional, Enterprise and standalone products, which Okta quotes on request.
  • Okta for Government, FedRAMP and US Military cells, and their exclusions.
  • Okta Verify, mobile apps and on-premises connectors, which are covered by order form supplements.

References

  1. Okta Product Subscription Reference GuideOkta guide titled "Okta Product Subscription Reference Guide 09-23-2026", Okta Workforce Identity section (pp.6-34). Catalog: Okta Product Subscription Reference Guide (September 2026)Effective 2026-09-23. Retrieved 2026-10-06.
  2. Okta Plans and PricingUndated price page. Catalog: Okta Plans and PricingRetrieved 2026-10-06.
  3. Okta Master Subscription Agreement (MSAQ1FY26)No effective date stated. Catalog: Okta Master Subscription Agreement (MSAQ1FY26)Retrieved 2026-10-06.
  4. Okta Free Trial Service-Specific TermsRev 04202026, s.3.3 Okta Platform Free Trial. Catalog: Okta Free Trial Service-Specific TermsEffective 2026-04-20. Retrieved 2026-10-06.
  5. Okta Customer Notice: Product Name UpdatesRev 052826. Catalog: Okta Customer Notice: Product Name Updates (May 2026)Effective 2026-05-28. Retrieved 2026-10-06.

See also

Catalog Rows Cited

11Rules5SKUs4Metrics2Programs

Esc