STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must enforce 24 hours/one day as the minimum password lifetime.

DISA Rule

SV-273200r1098867_rule

Vulnerability Number

V-273200

Group Title

SRG-APP-000173

Rule Version

OKTA-APP-000740

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy:
- Click "Edit".
- Set "Minimum password age is XX hours" to at least "24".

Check Contents

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy, verify "Minimum password age is XX hours" is set to at least "24".

For each policy, if "Minimum password age is XX hours" is not set to at least "24", this is a finding.

Vulnerability Number

V-273200

Documentable

False

Rule Version

OKTA-APP-000740

Severity Override Guidance

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy, verify "Minimum password age is XX hours" is set to at least "24".

For each policy, if "Minimum password age is XX hours" is not set to at least "24", this is a finding.

Check Content Reference

M

Target Key

5694