STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must be configured to accept Personal Identity Verification (PIV) credentials.

DISA Rule

SV-273204r1098879_rule

Vulnerability Number

V-273204

Group Title

SRG-APP-000391

Rule Version

OKTA-APP-001670

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Go to Security >> Authenticators.
2. In the "Setup" tab, click "Add authenticator".
3. Select the configured Smart Card Identity Provider and finish configuration.

Check Contents

From the Admin Console:
1. Go to Security >> Authenticators.
2. Verify that "Smart Card Authenticator" is listed and has "Status" listed as "Active".

If "Smart Card Authenticator" is not listed or is not listed as "Active", this is a finding.

Vulnerability Number

V-273204

Documentable

False

Rule Version

OKTA-APP-001670

Severity Override Guidance

From the Admin Console:
1. Go to Security >> Authenticators.
2. Verify that "Smart Card Authenticator" is listed and has "Status" listed as "Active".

If "Smart Card Authenticator" is not listed or is not listed as "Active", this is a finding.

Check Content Reference

M

Target Key

5694