Okta Workforce Identity licensing covers the Okta products a company uses to sign in, provision and govern its own employees, contractors and other workforce users. The Product Subscription Reference Guide (PSRG) says these products “are for use solely with Okta Workforce Identity Users”. A Workforce Identity User is an individual who uses the service to reach workforce applications such as human resources, productivity and custom-built workforce applications.[1] Whether a User qualifies as a Workforce Identity User “is at Okta’s sole and reasonable discretion”.[1] Okta sells Workforce Identity “as suites on a per-user, per-month basis” billed annually, and most products can also be bought on their own or added to a suite.[2] Users of customer-facing applications fall under Okta Customer Identity or Auth0 instead; see Okta Customer Identity and Auth0 licensing.
Editions
The PSRG lists six Workforce Identity Suites: Starter, Starter with Adaptive MFA, Core Essentials, Essentials, Professional and Enterprise. It also lists combined Professional and Enterprise Suites that include Okta Customer Identity B2C or B2B.[1] The suites are pre-packaged sets of products, “currently only available to new customers”, and must be bought “as a complete Suite rather than as individual components”.[1] Catalog: Suites are sold whole and only to new customers.
| Suite | List price (per user per month) | Components named by Okta |
|---|---|---|
| Starter | USD 6[2] | Universal Directory, Single Sign-On, MFA, Workflows (5 flows)[1] |
| Core Essentials | USD 14[2] | Offered as a lower-priced alternative to Essentials[2] |
| Essentials | USD 17[2] | Starter components with Adaptive MFA, plus Lifecycle Management, Access Governance, Workflows (50, 150 or Maximum flows) and Okta Privileged Access with 1 Resource Unit[1] |
| Professional | On request[2] | Essentials plus Device Access, Identity Threat Protection, ISPM (may be limited to 2 or 5 integrations), Maximum flows, Preview Sandbox and 0.5 Resource Units per user[1] |
| Enterprise | On request[2] | Professional plus API Access Management, Okta Access Gateway, ISPM (50 integrations) and 100,000 Machine to Machine Tokens per year[1] |
The PSRG’s entry for Core Essentials repeats the component list of Starter with Adaptive MFA, and the pricing page does not itemise it. A buyer should therefore confirm its contents on the Order Form. Products that are already part of a suite “cannot also be purchased alongside that Suite, except in limited circumstances”.[1]
Okta sometimes renames workforce SKUs. Older Order Forms may show names such as “IT Products - Lifecycle Management, 5 OIN Apps”, which became “IT Products - Lifecycle Management” in 2019. “Unlimited Workforce Identity Workflows” became “Workforce Identity Workflows (Maximum flows)” on 2026-05-14.[5] Catalog: Renamed products appear under new names on Order Forms.
Metrics
All Workforce Identity products use the Workforce Identity User as their unit. The MSA defines Users as “individuals (including non-human devices, such as applications or services)” who are authorised by the customer and for whom a subscription has been procured.[3] The PSRG makes the count concrete. Every User must have at least one subscription allocated, corresponding to a User ID in the Okta org.[1] Some products add secondary limits measured in other units: flows for Workflows (Active workflow), integrations for Identity Security Posture Management (ISPM Integration) and tokens for machine-to-machine API access (M2M Token).
Counting / floors
The Active Status rule
Okta “determines subscription compliance based on the count of User IDs” that have any of five statuses in Universal Directory: Active, Recovery, Locked-Out, Password Expired or Suspended.[1] Suspended and locked-out users therefore still consume a subscription, and a user stops counting only when deactivated. Each User ID is counted separately. This applies to non-human User IDs such as service accounts, to people who need more than one user type, and to Users assigned to several non-sandbox orgs, who need a separate User ID in each org.[1] The PSRG’s example is a teacher who enrols as a student at her own college. She needs a second profile with a Student user type and “a corresponding second subscription”.[1] Catalog: Compliance is measured by User IDs in an Active Status; Each User ID and each org is counted separately.
Product activation rules
Each product has its own activation rule, and the counts can differ inside one org.
| Product | Activation (what is counted) |
|---|---|
| Universal Directory | Users in an Active Status in the org[1] |
| Single Sign-On | Users in an Active Status with at least one application assigned; self-assigned personal applications do not count[1] |
| Single Sign-On (5 or 10 app limit) | As above, with up to 5 or 10 applications per User; the limit is per User, not per org[1] |
| MFA and Adaptive MFA | Users in an Active Status enrolled in an included factor (Okta Verify Push, SMS, Voice, YubiKey, WebAuthn, U2F, Custom OTP, Smart Card)[1] |
| Device Access | Users assigned to the Desktop MFA or Platform Single Sign-On for macOS application, or to an application whose sign-on policy uses an Advanced Posture Check[1] |
| API Access Management | Users assigned to OIDC applications with OAuth authorization provided by Okta[1] |
| Okta Access Gateway | Users assigned to active Access Gateway applications; no limit on applications[1] |
| Lifecycle Management | Users assigned to OIN applications with provisioning enabled, or all Users in an org where Lifecycle Management features (access request workflows, self-service registration, Org2Org) are enabled[1] |
| Workforce Identity Workflows | All Users in an org with at least one active workflow[1] |
| Access Governance (Okta Identity Governance) | All Users in an org where Access Governance features are enabled[1] |
| Identity Threat Protection | All Users in an org where Identity Threat Protection features are enabled[1] |
| Identity Security Posture Management | User IDs in the customer’s identity provider(s); each Active User in an integrated Okta org activates a subscription[1] |
Two patterns stand out. First, assignment-based products (Single Sign-On, API Access Management, Access Gateway, Device Access) count only users with a qualifying assignment or enrolment. Second, org-wide products (Lifecycle Management once its features are enabled, Workflows, Access Governance, Identity Threat Protection) count every Active User in the org as soon as a single feature is turned on. Catalog: Single Sign-On counts Users with at least one assigned application; Lifecycle Management can activate every User in the org.
Matching quantities and prerequisites
Several products must be bought in the same quantity as Universal Directory. For Workforce Identity Workflows, “The number of subscriptions purchased for Workforce Identity Workflows must match the number of subscriptions purchased for Universal Directory”.[1] The same matching rule applies to Okta Identity Governance and to Identity Threat Protection.[1] Workflows and Identity Governance customers must also buy a Single Sign-On licence for every Workflows administrator, with at least one Single Sign-On licence in total.[1] Catalog: Workflows, Identity Governance and Identity Threat Protection must match Universal Directory.
Other prerequisites:
- API Access Management and Okta Access Gateway require Single Sign-On.[1]
- Device Access requires MFA, Adaptive MFA or Single Sign-On. Advanced Posture Checks also need Adaptive MFA.[1]
- Lifecycle Management requires Universal Directory.[1]
- Identity Threat Protection requires Universal Directory, Single Sign-On and Adaptive MFA.[1]
- MFA and Adaptive MFA cannot be bought together. Neither includes the telephony that delivers SMS and Voice factors, so customers must configure an external telephony provider.[1] Catalog: MFA counts enrolled Users; telephony is not included.
Limits on flows and integrations
Workflows SKUs cap the number of active flows per org. Starter includes 5 flows, Essentials 50 (or 150 or Maximum as ordered), and Professional and Enterprise Maximum flows.[1] Customers of both Okta and Auth0 may extend up to five active workflows to Auth0. These count toward the flow limit but do not activate additional Workflows users.[1] Identity Security Posture Management allows up to 50 ISPM Integrations, or 2 or 5 on the limited SKUs. The 2-integration version is sold only within suites and covers one Okta org plus one of AWS, Azure Active Directory or Salesforce.[1]
Floors and growth
Okta Workforce Identity carries a “$1,500 annual contract minimum”.[2] For suites, Okta says that “all products share the same number of subscriptions”. Adding users for one product only is therefore not normally possible, except for Workflows, Okta Privileged Access and Machine-to-Machine tokens.[2] Catalog: Okta Workforce Identity has a USD 1,500 annual minimum; Extra licences are added to the whole suite.
A worked example
Take an org with 1,000 employees on Single Sign-On and Universal Directory, 40 service-account User IDs, 25 suspended leavers who have not been deactivated, and 30 contractors with no application assigned. Universal Directory counts every Active Status User ID: 1,000 + 40 + 25 + 30 = 1,095. Single Sign-On counts only those with an assigned application, which may be close to 1,000. If an administrator then activates a single workflow, Workforce Identity Workflows also counts all 1,095, and its quantity must match Universal Directory. The cheapest fix is usually administrative: deactivate leavers, review service accounts, and decide deliberately before switching on org-wide features. See true-up.
Virtualization & partitioning
Workforce Identity products are cloud services with no processor or virtualization rules. Separate orgs are the only partitioning that matters. A User assigned to several production orgs is counted in each, while sandbox orgs are excluded from the multi-org rule.[1] Multi-Org Deployment, which lets developers create orgs through the Org Creation API, is counted per Active org.[1]
Cloud / BYOL
Not applicable. Okta hosts the service. Machine-to-machine API traffic is licensed separately. The Machine-to-Machine Tokens SKU counts access tokens issued with the OAuth Client Credentials grant during each subscription year, and the Enterprise Suite includes 100,000 a year.[1]
Programs
- Workforce Identity Suites. See Editions above.
- Okta Platform Free Trial. Up to ten users may use Single Sign-On, Universal Directory, Adaptive MFA, Lifecycle Management, API Access Management, Device Access and Workflows for 30 days. Workflows is capped at five active flows and 1,000 executions, and there is no support. The trial is not available to public sector customers.[4] Catalog: Okta Platform Free Trial: 10 users for 30 days.
- Privileged access. Okta Privileged Access and Advanced Server Access use their own units. See Okta Privileged Access and AI agents licensing.
Out of scope
- Legacy Workforce SKUs listed in the separate Okta Legacy SKUs reference guide.
- Prices for Professional, Enterprise and standalone products, which Okta quotes on request.
- Okta for Government, FedRAMP and US Military cells, and their exclusions.
- Okta Verify, mobile apps and on-premises connectors, which are covered by order form supplements.