STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must validate passwords against a list of commonly used, expected, or compromised passwords.

DISA Rule

SV-273208r1099769_rule

Vulnerability Number

V-273208

Group Title

SRG-APP-000830

Rule Version

OKTA-APP-002980

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Navigate to Security >> Authenticators.
2. Click the "Actions" button next to the Password authenticator and select "Edit".
3. Under the "Password Settings" section, check the "Common Password Check" box.

Check Contents

From the Admin Console:
1. Navigate to Security >> Authenticators.
2. Click the "Actions" button next to the Password authenticator and select "Edit".
3. Under the "Password Settings" section, verify the "Common Password Check" box is checked.

If "Common Password Check" is not selected, this is a finding.

Vulnerability Number

V-273208

Documentable

False

Rule Version

OKTA-APP-002980

Severity Override Guidance

From the Admin Console:
1. Navigate to Security >> Authenticators.
2. Click the "Actions" button next to the Password authenticator and select "Edit".
3. Under the "Password Settings" section, verify the "Common Password Check" box is checked.

If "Common Password Check" is not selected, this is a finding.

Check Content Reference

M

Target Key

5694