STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Okta Global Session policy must be configured to allow or deny IP based access in accordance with the Access Control policy for Okta.

DISA Rule

SV-279691r1155072_rule

Vulnerability Number

V-279691

Group Title

SRG-APP-000033

Rule Version

OKTA-APP-003242

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:

1. Select the "Security" menu, and then click the "Global Session Policy" item.
2. In the Policy Settings section, configure the "IF User's IP is" setting to correctly set the appropriate network to either allow or deny based on the Access Control Policy.

Check Contents

From the Admin Console:

1. Select the "Security" menu, and then click the "Global Session Policy" item.
2. In the "Policy Settings" section, verify the "IF User's IP is" setting is correctly set to either allow or deny based on the organization defined policy.

If the Okta Global Session Policy is not configured to restrict access to specific IP ranges, this is a finding.

Vulnerability Number

V-279691

Documentable

False

Rule Version

OKTA-APP-003242

Severity Override Guidance

From the Admin Console:

1. Select the "Security" menu, and then click the "Global Session Policy" item.
2. In the "Policy Settings" section, verify the "IF User's IP is" setting is correctly set to either allow or deny based on the organization defined policy.

If the Okta Global Session Policy is not configured to restrict access to specific IP ranges, this is a finding.

Check Content Reference

M

Target Key

5694