STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta API tokens must be configured with Network Zones to restrict authorization from known networks.

DISA Rule

SV-279689r1155066_rule

Vulnerability Number

V-279689

Group Title

SRG-APP-001010

Rule Version

OKTA-APP-003240

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:

1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed, click the token name link.
4. In the "Security" section, click "Edit".
5. Set the "Token can be used from" setting to the known network zone for the application calling the API.
6. Click "Save".

Check Contents

From the Admin Console:

1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed, click the token name link.
4. In the "Security" section, verify the "Token can be used from" setting is mapped to a known network zone for the application calling the API.

If a network zone for each API access token is not defined, this is a finding.

Vulnerability Number

V-279689

Documentable

False

Rule Version

OKTA-APP-003240

Severity Override Guidance

From the Admin Console:

1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed, click the token name link.
4. In the "Security" section, verify the "Token can be used from" setting is mapped to a known network zone for the application calling the API.

If a network zone for each API access token is not defined, this is a finding.

Check Content Reference

M

Target Key

5694