STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must enforce a 60-day maximum password lifetime restriction.

DISA Rule

SV-273201r1098870_rule

Vulnerability Number

V-273201

Group Title

SRG-APP-000174

Rule Version

OKTA-APP-000745

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy:
- Click "Edit".
- Set "Password expires after XX days" to "60".

Check Contents

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy, verify "Password expires after XX days" is set to "60".

For each policy, if "Password expires after XX days" is not set to "60", this is a finding.

Vulnerability Number

V-273201

Documentable

False

Rule Version

OKTA-APP-000745

Severity Override Guidance

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy, verify "Password expires after XX days" is set to "60".

For each policy, if "Password expires after XX days" is not set to "60", this is a finding.

Check Content Reference

M

Target Key

5694