STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Okta Dashboard application must be configured to allow authentication only via non-phishable authenticators.

DISA Rule

SV-273190r1099763_rule

Vulnerability Number

V-273190

Group Title

SRG-APP-000065

Rule Version

OKTA-APP-000180

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Dashboard" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "Possession factor constraints are" section, ensure the "Phishing resistant" box is checked.

Check Contents

From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Dashboard" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "Possession factor constraints are" section, verify the "Phishing resistant" box is checked. This will ensure that only phishing-resistant factors are used to access the Okta Dashboard.

If in the "Possession factor constraints are" section the "Phishing resistant" box is not checked, this is a finding.

Vulnerability Number

V-273190

Documentable

False

Rule Version

OKTA-APP-000180

Severity Override Guidance

From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Dashboard" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "Possession factor constraints are" section, verify the "Phishing resistant" box is checked. This will ensure that only phishing-resistant factors are used to access the Okta Dashboard.

If in the "Possession factor constraints are" section the "Phishing resistant" box is not checked, this is a finding.

Check Content Reference

M

Target Key

5694