Plan for authentication changes
Map each connection to the applicable authentication milestone before setting a migration plan. Include the integration owner, test environment and recovery path.
Different authentication changes affect different users
Oracle’s 2026.2 authentication notes cover passkeys and upcoming integration restrictions. NLAuth integrations are scheduled to stop working in 2027.1, with an exception for existing IssueToken endpoint integrations. New TBA integrations will be restricted from 2027.1, while existing TBA integrations have a later transition.
Do not group all connection methods under one deadline. Identify the authentication method for each flow and ask its owner to verify the applicable notice. Keep secrets out of the inventory; record the method, system, owner and secure credential-management location instead.
Plan existing TBA connections with the right caveat
Oracle’s TBA preparation page identifies 2028.2 as a tentative later end-of-support target for existing integrations, with a stated SuiteAnalytics Connect exclusion. It directs affected integrations toward OAuth 2.0. A tentative date belongs in a reviewed plan, rather than being treated as an unconditional calendar commitment.
For third-party applications, confirm whether migration needs a connector update, a configuration change or a replacement flow. Document who performs each step and who validates the resulting business transactions.
Build an authentication inventory
Business purpose
Record what the flow accomplishes and what would stop if authentication failed. Include customer-facing consequences and any safe manual process.
Technical owner
Identify the internal maintainer and external supplier. Confirm who can obtain supported migration instructions and schedule a test.
Access scope
Record the role and permissions needed for the task. Review whether the integration can operate with a narrower, appropriate scope; do not expose credentials in project documents.
Evidence of recovery
Test an expired or unavailable credential in a safe environment. Confirm that the failure is visible to an owner and that recovery avoids duplicate or missing transactions.
Two additional 2027.1 access changes
| Announced change | Applicability and preparation |
|---|---|
| Employee-role 2FA | Oracle says the all-Employee-role 2FA feature will be enabled automatically in 2027.1. Administrators can disable it to restore the previous setting. For newly provisioned accounts, only roles already designated as 2FA-required will require it. Review the applicable account behavior and prepare users. |
| PKCE for new authorization-code integrations | New OAuth 2.0 authorization-code integrations will require PKCE parameters from 2027.1, including private clients. Existing integrations without PKCE remain functional. Include the requirement in new integration designs and supplier discussions. |
New and existing TBA connections have different timelines
- Does 2027.1 mean every TBA connection stops?
No. Oracle distinguishes restrictions on creating new integrations from the later end of support for existing ones. Check the exact notice and the method used by each connection.
