STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Okta Verify application must be configured to connect only to FIPS-compliant devices.

DISA Rule

SV-273205r1098882_rule

Vulnerability Number

V-273205

Group Title

SRG-APP-000395

Rule Version

OKTA-APP-001700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Go to Security >> Authenticators.
2. From the "Setup" tab, select "Edit Okta Verify".
3. In the "FIPS Compliance" field, choose whether users enrolling in Okta Verify can use FIPS-compliant devices only or any device.
4. Click "Save" after making any changes.

Check Contents

From the Admin Console:
1. Go to Security >> Authenticators.
2. From the "Setup" tab, select "Edit Okta Verify".
3. Review the "FIPS Compliance" field.

If FIPS-compliant authentication is not enabled, this is a finding.

Vulnerability Number

V-273205

Documentable

False

Rule Version

OKTA-APP-001700

Severity Override Guidance

From the Admin Console:
1. Go to Security >> Authenticators.
2. From the "Setup" tab, select "Edit Okta Verify".
3. Review the "FIPS Compliance" field.

If FIPS-compliant authentication is not enabled, this is a finding.

Check Content Reference

M

Target Key

5694