STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must enforce a minimum 15-character password length.

DISA Rule

SV-273195r1098852_rule

Vulnerability Number

V-273195

Group Title

SRG-APP-000164

Rule Version

OKTA-APP-000650

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy:
- Click "Edit".
- Set the "Minimum Length" field to at least "15" characters.

Check Contents

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy, verify the "Minimum Length" field is set to at least "15" characters.

If any policy is not set to at least "15", this is a finding.

Vulnerability Number

V-273195

Documentable

False

Rule Version

OKTA-APP-000650

Severity Override Guidance

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy, verify the "Minimum Length" field is set to at least "15" characters.

If any policy is not set to at least "15", this is a finding.

Check Content Reference

M

Target Key

5694