SV-279689r1155066_rule
V-279689
SRG-APP-001010
OKTA-APP-003240
CAT II
10
From the Admin Console:
1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed, click the token name link.
4. In the "Security" section, click "Edit".
5. Set the "Token can be used from" setting to the known network zone for the application calling the API.
6. Click "Save".
From the Admin Console:
1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed, click the token name link.
4. In the "Security" section, verify the "Token can be used from" setting is mapped to a known network zone for the application calling the API.
If a network zone for each API access token is not defined, this is a finding.
V-279689
False
OKTA-APP-003240
From the Admin Console:
1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed, click the token name link.
4. In the "Security" section, verify the "Token can be used from" setting is mapped to a known network zone for the application calling the API.
If a network zone for each API access token is not defined, this is a finding.
M
5694