STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must automatically disable accounts after a 35-day period of account inactivity.

DISA Rule

SV-273188r1098831_rule

Vulnerability Number

V-273188

Group Title

SRG-APP-000025

Rule Version

OKTA-APP-000090

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Go to Workflow >> Automations and select "Add Automation".
2. Create a name for the Automation (e.g., "User Inactivity").
3. Click "Add Condition" and select "User Inactivity in Okta".
4. In the duration field, enter 35 days and click "Save".
5 Click the edit button next to "Select Schedule".
6. Configure the "Schedule" field for "Run Daily" and set the "Time" field to an organizationally defined time to run this automation. Click "Save".
7. Click the edit button next to "Select group membership".
8. In the "Applies to" field, select the group "Everyone" by typing it into the field. Click "Save".
9. Click "Add Action" and select "Change User lifecycle state in Okta".
10. In the "Change user state to" field, select "Suspended" and click "Save".
11. Click the "Inactive" button near the top of the section screen and select "Activate".

Check Contents

If Okta Services rely on external directory services for user sourcing, this is not applicable, and the connected directory services must perform this function.

Go to Workflows >> Automations and verify that an Automation has been created to disable accounts after 35 days of inactivity.

If the Okta configuration does not automatically disable accounts after a 35-day period of account inactivity, this is a finding.

Vulnerability Number

V-273188

Documentable

False

Rule Version

OKTA-APP-000090

Severity Override Guidance

If Okta Services rely on external directory services for user sourcing, this is not applicable, and the connected directory services must perform this function.

Go to Workflows >> Automations and verify that an Automation has been created to disable accounts after 35 days of inactivity.

If the Okta configuration does not automatically disable accounts after a 35-day period of account inactivity, this is a finding.

Check Content Reference

M

Target Key

5694