STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must be configured with Network Zones defined to block anonymized proxies according to organizationally defined policy.

DISA Rule

SV-279692r1155075_rule

Vulnerability Number

V-279692

Group Title

SRG-APP-000039

Rule Version

OKTA-APP-003243

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:

1. Select the "Security" menu, and then click the "Networks" item.
2. If the CSSP has provided a list of anonymizers to block, add the IP ranges to the "IP Block list".
a. Click the pencil icon next to IP Block list.
b. Add the IP ranges to the "Gateway IPs" section and click "Save".
3. If the CSSP is not able to provide a list, then implement the Okta managed list.
a. Set the "Enhanced dynamic zone blocklist" to "Active".

Check Contents

From the Admin Console:

1. Select the "Security" menu, and then click the "Networks' item.
2. If the CSSP has provided a list of anonymizers to block, verify the "IP Block list" is configured with them.
a. Click the pencil icon next to IP Block list.
b. Verify the "Gateway IPs" section contains all of the IP ranges in the provided list.
3. If the CSSP is not able to provide a list, then implement the Okta managed list.
a. Verify the "Enhanced dynamic zone blocklist" is set to "Active".

If Network Zones are not configured to block anonymous proxies, this is a finding.

Vulnerability Number

V-279692

Documentable

False

Rule Version

OKTA-APP-003243

Severity Override Guidance

From the Admin Console:

1. Select the "Security" menu, and then click the "Networks' item.
2. If the CSSP has provided a list of anonymizers to block, verify the "IP Block list" is configured with them.
a. Click the pencil icon next to IP Block list.
b. Verify the "Gateway IPs" section contains all of the IP ranges in the provided list.
3. If the CSSP is not able to provide a list, then implement the Okta managed list.
a. Verify the "Enhanced dynamic zone blocklist" is set to "Active".

If Network Zones are not configured to block anonymous proxies, this is a finding.

Check Content Reference

M

Target Key

5694