STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must prohibit password reuse for a minimum of five generations.

DISA Rule

SV-273209r1098894_rule

Vulnerability Number

V-273209

Group Title

SRG-APP-000845

Rule Version

OKTA-APP-003010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password" row and select "Edit".
3. For each listed policy:
- Click "Edit".
- Set "Enforce password history for last XX passwords" to "5".

Check Contents

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password row" and select "Edit".
3. For each listed policy, verify "Enforce password history for last XX passwords" is set to "5".

If any policy is not set to at least "5", this is a finding.

Vulnerability Number

V-273209

Documentable

False

Rule Version

OKTA-APP-003010

Severity Override Guidance

From the Admin Console:
1. Select Security >> Authenticators.
2. Click the "Actions" button next to the "Password row" and select "Edit".
3. For each listed policy, verify "Enforce password history for last XX passwords" is set to "5".

If any policy is not set to at least "5", this is a finding.

Check Content Reference

M

Target Key

5694