diff --git a/locale/no_NO/LC_MESSAGES/django.po b/locale/no_NO/LC_MESSAGES/django.po
index e2879075be..febd9c4e15 100644
--- a/locale/no_NO/LC_MESSAGES/django.po
+++ b/locale/no_NO/LC_MESSAGES/django.po
@@ -12,7 +12,7 @@ msgid ""
msgstr ""
"Project-Id-Version: PACKAGE VERSION\n"
"Report-Msgid-Bugs-To: \n"
-"POT-Creation-Date: 2026-04-23 00:25+0000\n"
+"POT-Creation-Date: 2026-05-06 00:27+0000\n"
"PO-Revision-Date: 2025-12-01 19:09+0000\n"
"Last-Translator: Raphael Cancelliere, 2026\n"
"Language-Team: Norwegian (Norway) (https://app.transifex.com/authentik/teams/119923/no_NO/)\n"
@@ -109,6 +109,14 @@ msgstr "Valideringsfeil"
msgid "Blueprint file does not exist"
msgstr "Blueprint-filen eksisterer ikke"
+#: authentik/blueprints/api.py
+msgid "Context must be valid JSON"
+msgstr ""
+
+#: authentik/blueprints/api.py
+msgid "Context must be a JSON object"
+msgstr ""
+
#: authentik/blueprints/api.py
msgid "Failed to validate blueprint"
msgstr "Klarte ikke å validere blueprint"
@@ -247,6 +255,14 @@ msgstr ""
" kun backchannel-leverandører. Når satt til false, ekskluderes backchannel-"
"leverandører."
+#: authentik/core/api/users.py
+msgid "Invalid password hash format. Must be a valid Django password hash."
+msgstr ""
+
+#: authentik/core/api/users.py
+msgid "Cannot set both password and password_hash. Use only one."
+msgstr ""
+
#: authentik/core/api/users.py
msgid "No leading or trailing slashes allowed."
msgstr "Ingen skråstreker i starten eller slutten er tillatt."
@@ -421,6 +437,10 @@ msgstr "Internt applikasjonsnavn, brukt i URL-er."
msgid "Open launch URL in a new browser tab or window."
msgstr "Åpne start-URL i en ny nettleserfane eller -vindu."
+#: authentik/core/models.py
+msgid "Hide this application from the user's My applications page."
+msgstr ""
+
#: authentik/core/models.py
msgid "Application"
msgstr "Applikasjon"
@@ -917,10 +937,6 @@ msgstr "Enten en vurderingsgruppe eller en vurderer må være angitt."
msgid "Grace period must be shorter than the interval."
msgstr "Respittiden må være kortere enn intervallet."
-#: authentik/enterprise/lifecycle/api/rules.py
-msgid "Only one type-wide rule for each object type is allowed."
-msgstr "Kun én type-omfattende regel for hver objekttype er tillatt."
-
#: authentik/enterprise/lifecycle/models.py
msgid ""
"Select which transports should be used to notify the reviewers. If none are "
@@ -950,9 +966,9 @@ msgid "Go to {self._get_model_name()}"
msgstr "Gå til {self._get_model_name()}"
#: authentik/enterprise/lifecycle/models.py
-msgid "Access review is due for {self.content_type.name} {str(self.object)}"
+msgid ""
+"Access review is due for {self.content_type.name.lower()} {object_label}"
msgstr ""
-"Tilgangsvurdering forfaller for {self.content_type.name} {str(self.object)}"
#: authentik/enterprise/lifecycle/models.py
msgid ""
@@ -968,8 +984,8 @@ msgstr ""
"Tilgangsvurdering fullført for {self.content_type.name} {str(self.object)}"
#: authentik/enterprise/lifecycle/tasks.py
-msgid "Dispatch tasks to validate lifecycle rules."
-msgstr "Send ut oppgaver for å validere livssyklusregler."
+msgid "Dispatch tasks to apply lifecycle rules."
+msgstr ""
#: authentik/enterprise/lifecycle/tasks.py
msgid "Apply lifecycle rule."
@@ -1305,6 +1321,78 @@ msgstr "Last ned"
msgid "Generate data export."
msgstr "Generer eksport av data."
+#: authentik/enterprise/stages/account_lockdown/api.py
+msgid "User to lock. If omitted, locks the current user (self-service)."
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/api.py
+msgid "No lockdown flow configured."
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/api.py
+msgid "Lockdown flow is not applicable."
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/api.py
+msgid "Choose the target account, then return a flow link."
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/api.py
+msgid "No lockdown flow configured or the flow is not applicable"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/api.py
+msgid "Permission denied (when targeting another user)"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/models.py
+msgid "Deactivate the user account (set is_active to False)"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/models.py
+msgid "Set an unusable password for the user"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/models.py
+msgid "Delete all active sessions for the user"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/models.py
+msgid ""
+"Revoke all tokens for the user (API, app password, recovery, verification, "
+"OAuth)"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/models.py
+msgid ""
+"Flow to redirect users to after self-service lockdown. This flow should not "
+"require authentication since the user's session is deleted."
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/models.py
+msgid "Account Lockdown Stage"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/models.py
+msgid "Account Lockdown Stages"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/stage.py
+msgid "No target user specified for account lockdown"
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/stage.py
+msgid "You do not have permission to lock down this account."
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/stage.py
+msgid "Account lockdown failed for this account."
+msgstr ""
+
+#: authentik/enterprise/stages/account_lockdown/stage.py
+msgid "Self-service account lockdown requires a completion flow."
+msgstr ""
+
#: authentik/enterprise/stages/authenticator_endpoint_gdtc/models.py
msgid "Endpoint Authenticator Google Device Trust Connector Stage"
msgstr "Trinn for endepunktautentisering via Google Device Trust-kobling"
@@ -2705,8 +2793,10 @@ msgstr ""
" vil ingen målgrupperestriksjon bli lagt til."
#: authentik/providers/saml/models.py
-msgid "Also known as EntityID"
-msgstr "Også kjent som EntityID"
+msgid ""
+"Also known as EntityID. Providing a value overrides the default issuer "
+"generated by authentik."
+msgstr ""
#: authentik/providers/saml/models.py
msgid "SLS URL"
@@ -2924,6 +3014,10 @@ msgstr "SAML NameID-verdi for denne økten"
msgid "SAML NameID format"
msgstr "SAML NameID-format"
+#: authentik/providers/saml/models.py
+msgid "SAML Issuer used for this session"
+msgstr ""
+
#: authentik/providers/saml/models.py
msgid "SAML Session"
msgstr "SAML-økt"
@@ -2956,6 +3050,10 @@ msgstr "Salesforce"
msgid "Webex"
msgstr "Webex"
+#: authentik/providers/scim/models.py
+msgid "vCenter"
+msgstr ""
+
#: authentik/providers/scim/models.py
msgid "Group filters used to define sync-scope for groups."
msgstr "Gruppefiltre brukt for å definere synkroniseringsomfang for grupper."
@@ -4830,6 +4928,18 @@ msgstr "Skjult: Skjult felt, kan brukes til å sette inn data i skjemaet."
msgid "Static: Static value, displayed as-is."
msgstr "Statisk: Statisk verdi, vises som den er."
+#: authentik/stages/prompt/models.py
+msgid "Alert (Info): Static alert box with info styling"
+msgstr ""
+
+#: authentik/stages/prompt/models.py
+msgid "Alert (Warning): Static alert box with warning styling"
+msgstr ""
+
+#: authentik/stages/prompt/models.py
+msgid "Alert (Danger): Static alert box with danger styling"
+msgstr ""
+
#: authentik/stages/prompt/models.py
msgid "authentik: Selection of locales authentik supports"
msgstr "authentik: Utvalg av språk som authentik støtter"
diff --git a/web/xliff/no_NO.xlf b/web/xliff/no_NO.xlf
index 3b68fc1cd7..63f326f735 100644
--- a/web/xliff/no_NO.xlf
+++ b/web/xliff/no_NO.xlf
@@ -1326,10 +1326,6 @@
Open in new tabÅpne i ny fane
-
- If checked, the launch URL will open in a new browser tab or window from the user's application library.
- Hvis krysset av, vil start-URL åpnes i en ny fane eller et nytt vindu fra brukerens applikasjonsbibliotek.
-Select all rowsVelg alle rader
@@ -1414,18 +1410,10 @@
PolicyPolicy
-
- Negate result
- Inverter resultat
-Negates the outcome of the binding. Messages are unaffected.Inverterer utfallet av bindingen. Meldinger påvirkes ikke.
-
- Failure result
- Feilresultat
-Enterprise onlyKun Enterprise
@@ -2246,10 +2234,6 @@
IssuerUtsteder
-
- Also known as Entity ID.
- Også kjent som Enhets-ID.
-AudiencePublikum
@@ -3922,14 +3906,6 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
Application entitlementsApplikasjonsrettigheter
-
- Application entitlements are in preview.
- Applikasjonsrettigheter er i forhåndsvisning.
-
-
- Send us feedback!
- Send oss tilbakemelding!
-These entitlements can be used to configure user access in this application.Disse rettighetene kan brukes til å konfigurere brukertilgang i denne applikasjonen.
@@ -4466,10 +4442,6 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
TLS Verification CertificateTLS-verifiseringssertifikat
-
- When connecting to an LDAP Server with TLS, certificates are not checked by default. Specify a keypair to validate the remote certificate.
- Ved tilkobling til en LDAP-server med TLS, sjekkes ikke sertifikater som standard. Spesifiser et nøkkelpar for å validere fjerneresertifikatet.
-TLS Client authentication certificateTLS-klientautentiseringssertifikat
@@ -5453,8 +5425,7 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
Aktiver
- Update 's password
- Oppdater passordet til
+ Update 's passwordSet password
@@ -5536,10 +5507,6 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
User SearchBrukersøk
-
- Warning: You're about to delete the user you're logged in as (). Proceed at your own risk.
- Advarsel: Du er i ferd med å slette brukeren du er logget inn som (). Fortsett på eget ansvar.
-Show deactivated usersVis deaktiverte brukere
@@ -6352,10 +6319,6 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
Stage used to validate any authenticator. This stage should be used during authentication or authorization flows.Trinn brukt for å validere enhver autentisator. Dette trinnet bør brukes under autentiserings- eller autorisasjonsflyter.
-
- Device classes
- Enhetsklasser
-Device classes which can be used to authenticate.Enhetsklasser som kan brukes til å autentisere.
@@ -6480,18 +6443,6 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
Authenticator AttachmentAutentisatorvedlegg
-
- No preference is sent
- Ingen preferanse sendes
-
-
- A non-removable authenticator, like TouchID or Windows Hello
- En ikke-flyttbar autentisator, som TouchID eller Windows Hello
-
-
- A "roaming" authenticator, like a YubiKey
- En "roaming"-autentisator, som en YubiKey
-Maximum registration attemptsMaksimalt antall registreringsforsøk
@@ -6600,10 +6551,6 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
Let the user identify themselves with their username or Email address.La brukeren identifisere seg med sitt brukernavn eller e-postadresse.
-
- User fields
- Brukerfelt
-Fields a user can identify themselves with. If no fields are selected, the user will only be able to use sources.Felt en bruker kan identifisere seg med. Hvis ingen felt er valgt, vil brukeren bare kunne bruke kilder.
@@ -6832,10 +6779,6 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
Selected policies are executed when the stage is submitted to validate the data.Valgte policyer kjøres når trinnet sendes inn for å validere dataene.
-
- Redirect the user to another flow, potentially with all gathered context
- Omdiriger brukeren til en annen flyt, potensielt med all innhentet kontekst
-StaticStatisk
@@ -7460,10 +7403,6 @@ består ikke når ett eller begge av de valgte alternativene er lik eller over t
Select the group of users which the alerts are sent to. Velg gruppen brukere varslene sendes til.
-
- If no group is selected and 'Send notification to event user' is disabled the rule is disabled.
- Hvis ingen gruppe er valgt og 'Send varsel til hendelsesbruker' er deaktivert, er regelen deaktivert.
-Send notification to event userSend varsel til hendelsesbruker
@@ -8876,10 +8815,6 @@ Bindinger til grupper/brukere sjekkes mot brukeren av hendelsen.
UngroupedUgruppert
-
- My Applications
- Mine applikasjoner
-Search for an application by name...Søk etter en applikasjon ved navn...
@@ -8888,10 +8823,6 @@ Bindinger til grupper/brukere sjekkes mot brukeren av hendelsen.
Search returned no results.Søket ga ingen resultater.
-
- My applications
- Mine applikasjoner
-Application listApplikasjonsliste
@@ -9437,10 +9368,6 @@ Bindinger til grupper/brukere sjekkes mot brukeren av hendelsen.
Maximum page size for API requests.Maksimal sidestørrelse for API-forespørsler.
-
- When enabled, notification will be sent to the user that triggered the event in addition to any users in the group above. The event user will always be the first user, to send a notification only to the event user enabled 'Send once' in the notification transport. If no group is selected and 'Send notification to event user' is disabled the rule is disabled.
- Når aktivert, vil varsel bli sendt til brukeren som utløste hendelsen, i tillegg til eventuelle brukere i gruppen ovenfor. Hendelsesbrukeren vil alltid være den første brukeren, for å sende et varsel kun til hendelsesbrukeren, aktiver 'Send én gang' i varslingstransporten. Hvis ingen gruppe er valgt og 'Send varsel til hendelsesbruker' er deaktivert, er regelen deaktivert.
-Local connectionLokal tilkobling
@@ -10141,18 +10068,10 @@ Bindinger til grupper/brukere sjekkes mot brukeren av hendelsen.
Reviewer groupsGjennomgangsgrupper
-
- Min reviewers
- Min. antall gjennomgangspersoner
-Number of users from the selected reviewer groups that must approve the review.Antall brukere fra de valgte gjennomgangsgruppene som må godkjenne gjennomgangen.
-
- Min reviewers is per-group
- Min. antall gjennomgangspersoner er per gruppe
-ReviewersGjennomgangspersoner
@@ -11215,10 +11134,6 @@ Bindinger til grupper/brukere sjekkes mot brukeren av hendelsen.
Search for a lifecycle rule by name or target...Søk etter en livssyklusregel ved navn eller mål...
-
- Search tasks...
- Søk i oppgaver...
-ReviewGjennomgang
@@ -11772,10 +11687,6 @@ Bindinger til grupper/brukere sjekkes mot brukeren av hendelsen.
Require Flow token (flow can only be executed from a generated recovery link)Krev flyt-token (flyt kan bare utføres fra en generert gjenopprettingslenke)
-
- Bind New Policy
- Bind ny policy
-Select the type of policy you want to create.Velg typen policy du ønsker å opprette.
@@ -11852,10 +11763,6 @@ Bindinger til grupper/brukere sjekkes mot brukeren av hendelsen.
Review ActivationSe over aktivering av
-
- Objects associated with this user
- Objekter tilknyttet denne brukeren
-ObjectsObjekter
@@ -11965,6 +11872,319 @@ Bindinger til grupper/brukere sjekkes mot brukeren av hendelsen.
er ikke tilknyttet noen objekter.Zero: no objects use this entity.
+
+ Authorization Code
+
+
+ Implicit
+
+
+ Hybrid
+
+
+ Refresh token
+
+
+ Client credentials
+
+
+ Device-code
+
+
+ Grant Types
+
+
+ Grant types this provider may use.
+
+
+ vCenter
+
+
+ Altered behavior for usage with VMware vCenter.
+
+
+ EntityID/Issuer override
+
+
+ Sets a custom EntityID/Issuer to override the authentik generated default.
+
+
+ Passwords
+
+
+ Setting
+
+
+ Type a new password...
+
+
+ When enabled, your username will be remembered on this device for future logins.
+
+
+ ...
+ The message shown while a form is being submitted, when no entity name is provided.
+
+
+ Account lockdown flow
+
+
+ Select an account lockdown flow...
+
+
+ Flow used when a user triggers account lockdown (e.g. in case of compromise). Should contain an Account Lockdown stage.
+
+
+ Account lockdown flows should require authentication so they can only be started from a signed-in session.
+
+
+ If no group is selected and 'Send notification to event user' is disabled, the rule is disabled.
+
+
+ When enabled, notification will be sent to the user that triggered the event in addition to any users in the group above. The event user will always be the first user, to send a notification only to the event user enabled 'Send once' in the notification transport.
+
+
+ Minimum reviewers
+
+
+ Minimum reviewers is per-group
+
+
+ The following reviews apply to this object:
+
+
+ This object has no reviews yet.
+
+
+ Rule
+
+
+ This stage executes account lockdown actions on a target user. Configure which actions to perform when this stage runs.
+
+
+ Type a name for this stage...
+
+
+ Deactivate user
+
+
+ Deactivate the user account (set is_active to False).
+
+
+ Set unusable password
+
+
+ Set an unusable password for the user.
+
+
+ Delete sessions
+
+
+ Delete all active sessions for the user.
+
+
+ Revoke tokens
+
+
+ Revoke all tokens for the user (API, app password, recovery, verification).
+
+
+ Self-service completion
+
+
+ Configure what happens after a user locks their own account. Since all sessions are deleted, the user cannot continue in the current flow and will be redirected to a separate completion flow.
+
+
+ Completion flow
+
+
+ Select a completion flow...
+
+
+ Flow to redirect users to after self-service lockdown. This flow must not require authentication since the user's session is deleted.
+
+
+ Alert (Info): Static alert box with info styling
+
+
+ Alert (Warning): Static alert box with warning styling
+
+
+ Alert (Danger): Static alert box with danger styling
+
+
+ Warning: You are about to delete user , but you are currently logged in as this user. Proceed at your own risk.
+
+
+ Account Lockdown
+
+
+ Security
+
+
+ If you suspect your account has been compromised, you can immediately lock it to prevent unauthorized access.
+
+
+ Lock my account
+
+
+ Bind existing group/user
+
+
+ Leave empty to skip certificate validation, or select a certificate/keypair containing the LDAP server CA chain to validate the remote certificate.
+
+
+ Choose Policy Type
+
+
+ Negate Result
+
+
+ Failure Result
+
+
+ Device Classes
+
+
+ User Fields
+
+
+ This flag is deprecated.
+
+
+ If checked, the launch URL will open in a new browser tab or window from the user's application library.
+ Hvis krysset av, vil start-URL åpnes i en ny fane eller et nytt vindu fra brukerens applikasjonsbibliotek.
+
+
+ Hide from My applications
+
+
+ If checked, this application will not be shown on the user's My applications page.
+
+
+ No preference: the browser may offer any available authenticator
+
+
+ Platform: a non-removable authenticator built into the device, such as Touch ID, Face ID, or Windows Hello
+
+
+ Cross-platform: a roaming authenticator, such as a YubiKey or Google Titan
+
+
+ Controls the authenticatorAttachment parameter sent to the browser during WebAuthn registration. If Hints are configured and this is left as 'No preference', a value is inferred from the selected hints for backward compatibility with older browsers.
+
+
+ New Invitation
+
+
+ New Invitation options
+
+
+ Opens the new invitation wizard and binds the invitation to an existing enrollment flow.
+
+
+ with Existing Enrollment Flow...
+
+
+ Opens the new invitation wizard, which will create a new enrollment flow and invitation stage.
+
+
+ with New Enrollment Flow and Invitation Stage...
+
+
+ Create a new invitation with an enrollment flow.
+
+
+ Enrollment Flow
+
+
+ Invitation Details
+
+
+ Invitation Link
+
+
+ failed
+
+
+ Importing enrollment flow blueprint
+
+
+ Blueprint validation failed
+
+
+ Flow with slug "" not found after import
+
+
+ Creating invitation
+
+
+ The flow selected in the previous step. The invitation will be bound to this flow.
+
+
+ No invitation available to send
+
+
+ Failed to queue invitation emails
+
+
+ No enrollment flows with invitation stages found
+
+
+ You can create a new enrollment flow and invitation stage right here, or cancel and bind an invitation stage to an existing flow manually.
+
+
+ Create a new enrollment flow
+
+
+ Only enrollment flows that have an invitation stage bound to them are listed here.
+
+
+ Flow name
+
+
+ Name for the new enrollment flow.
+
+
+ Flow slug
+
+
+ Invitation stage name
+
+
+ Name for the new invitation stage.
+
+
+ Enrolled users are created as external (e.g. customers, guests). New users will be placed under users/external.
+
+
+ Enrolled users are created as internal (e.g. employees). New users will be placed under users/internal.
+
+
+ If enabled, the stage will jump to the next stage when no invitation is given. If disabled, the flow will be cancelled without a valid invitation.
+
+
+ No invitation was created.
+
+
+ Redirect the user to a static URL or another flow, optionally with all gathered context.
+
+
+ The element could not be loaded. This may be due to a missing import or a version mismatch.
+
+
+ An element could not be loaded. Please try refreshing the page or clearing your cache.
+
+
+ Failed to load element
+
+
+ My Applications
+ Mine applikasjoner
+
+
+ My applications
+ Mine applikasjoner
+