STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must enforce the limit of three consecutive invalid login attempts by a user during a 15-minute time period.

DISA Rule

SV-273189r1098834_rule

Vulnerability Number

V-273189

Group Title

SRG-APP-000065

Rule Version

OKTA-APP-000170

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Go to Security >> Authenticators.
2. Click the "Actions" button next to "Password" and select "Edit".
3. For each Password Policy, ensure the "Lock Out" section has the following values:
- "Lock out after 3 unsuccessful attempts" is checked.
- The value is set to "3".

Check Contents

If Okta Services rely on external directory services for user sourcing, this check is not applicable, and the connected directory services must perform this function.

From the Admin Console:
1. Go to Security >> Authenticators.
2. Click the "Actions" button next to "Password" and select "Edit".
3. For each Password Policy, verify the "Lock Out" section has the following values:
- "Lock out after 3 unsuccessful attempts" is checked.
- The value is set to "3".

If Okta Services are not configured to automatically lock user accounts after three consecutive invalid login attempts, this is a finding.

Vulnerability Number

V-273189

Documentable

False

Rule Version

OKTA-APP-000170

Severity Override Guidance

If Okta Services rely on external directory services for user sourcing, this check is not applicable, and the connected directory services must perform this function.

From the Admin Console:
1. Go to Security >> Authenticators.
2. Click the "Actions" button next to "Password" and select "Edit".
3. For each Password Policy, verify the "Lock Out" section has the following values:
- "Lock out after 3 unsuccessful attempts" is checked.
- The value is set to "3".

If Okta Services are not configured to automatically lock user accounts after three consecutive invalid login attempts, this is a finding.

Check Content Reference

M

Target Key

5694