SV-273190r1099763_rule
V-273190
SRG-APP-000065
OKTA-APP-000180
CAT II
10
From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Dashboard" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "Possession factor constraints are" section, ensure the "Phishing resistant" box is checked.
From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Dashboard" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "Possession factor constraints are" section, verify the "Phishing resistant" box is checked. This will ensure that only phishing-resistant factors are used to access the Okta Dashboard.
If in the "Possession factor constraints are" section the "Phishing resistant" box is not checked, this is a finding.
V-273190
False
OKTA-APP-000180
From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Dashboard" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "Possession factor constraints are" section, verify the "Phishing resistant" box is checked. This will ensure that only phishing-resistant factors are used to access the Okta Dashboard.
If in the "Possession factor constraints are" section the "Phishing resistant" box is not checked, this is a finding.
M
5694