STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Okta Admin Console application must be configured to use multifactor authentication.

DISA Rule

SV-273193r1098846_rule

Vulnerability Number

V-273193

Group Title

SRG-APP-000149

Rule Version

OKTA-APP-000560

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Admin Console" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "User must authenticate with" field, select either "Password/IdP + Another factor" or "Any 2 factor types".

Check Contents

From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Admin Console" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "User must authenticate with" field, verify that either "Password/IdP + Another factor" or "Any 2 factor types" is selected.

If either of these settings is incorrect, this is a finding.

Vulnerability Number

V-273193

Documentable

False

Rule Version

OKTA-APP-000560

Severity Override Guidance

From the Admin Console:
1. Go to Security >> Authentication Policies.
2. Click the "Okta Admin Console" policy.
3. Click the "Actions" button next to the top rule and select "Edit".
4. In the "User must authenticate with" field, verify that either "Password/IdP + Another factor" or "Any 2 factor types" is selected.

If either of these settings is incorrect, this is a finding.

Check Content Reference

M

Target Key

5694