STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

For each application integrated with Okta, network zones must be defined in its authentication policy.

DISA Rule

SV-279693r1155078_rule

Vulnerability Number

V-279693

Group Title

SRG-APP-000039

Rule Version

OKTA-APP-003244

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

For each application, starting at the admin console:

1. Open the "Applications" group from the Menu, and then click the "Applications" menu item.
2. Click the application name.
3. Click the "Sign On" tab.
4. Scroll to the "User Authentication" section, and then click "Edit".
5. Select the appropriate Authentication policy from the pull down, and then click "Save".
6. Click "View Policy Details".
7. For each nondefault rule:
a. Select "Edit" from the Actions menu.
b. In the "IF" section, verify the "User is" setting has the appropriate allow or deny range has been selected based on the Access Control policy for the application.
c. Scroll down to the bottom and click "Save".
8. For the Catch-All rule:
a. Select "Edit" from the Actions menu.
b. Scroll down to the "Then" section.
c. For the "Access is" setting, select "Denied", and then click "Save".

Check Contents

For each application integrated into Okta:

1. From the Admin console, open the "Security" menu, and then select "Networks".
2. Verify the list of networks includes all necessary allow or block lists.

If any application is not configured with network zones, this is a finding.

Vulnerability Number

V-279693

Documentable

False

Rule Version

OKTA-APP-003244

Severity Override Guidance

For each application integrated into Okta:

1. From the Admin console, open the "Security" menu, and then select "Networks".
2. Verify the list of networks includes all necessary allow or block lists.

If any application is not configured with network zones, this is a finding.

Check Content Reference

M

Target Key

5694