STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta API tokens must be created under new dedicated user accounts.

DISA Rule

SV-279690r1155069_rule

Vulnerability Number

V-279690

Group Title

SRG-APP-001010

Rule Version

OKTA-APP-003241

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:

1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed that has "Super Admin" or an improperly scoped Admin account, delete the token and create a new one with the appropriately scoped permissions.
4. Verify the application performing the API calls with the new token has been updated.

Check Contents

From the Admin Console:

1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed, verify that the Role listed is not "Super Admin", and that the account has been specifically created for that token.
4. Click the account name to be token to the user profile for that user.
5. Verify the user only has an administrator role (standard or customer) applied that is correctly scoped as required and documented in the Okta Access Control policy.

If the token is using a Super Administrator account, or one that is not properly scoped per the Access Control policy, this is a finding.

Note: If a Super Admin token is required for system operation, then this permanent finding.

Vulnerability Number

V-279690

Documentable

False

Rule Version

OKTA-APP-003241

Severity Override Guidance

From the Admin Console:

1. Select the "Security" menu, and then click the "API" item.
2. Click the "Tokens" tab.
3. For each token listed, verify that the Role listed is not "Super Admin", and that the account has been specifically created for that token.
4. Click the account name to be token to the user profile for that user.
5. Verify the user only has an administrator role (standard or customer) applied that is correctly scoped as required and documented in the Okta Access Control policy.

If the token is using a Super Administrator account, or one that is not properly scoped per the Access Control policy, this is a finding.

Note: If a Super Admin token is required for system operation, then this permanent finding.

Check Content Reference

M

Target Key

5694