STIGQter STIGQter: STIG Summary:

Okta Identity as a Service (IDaaS) Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-273186r1098825_ruleOkta must log out a session after a 15-minute period of inactivity.
SV-273187r1098828_ruleThe Okta Admin Console must log out a session after a 15-minute period of inactivity.
SV-273188r1098831_ruleOkta must automatically disable accounts after a 35-day period of account inactivity.
SV-273189r1098834_ruleOkta must enforce the limit of three consecutive invalid login attempts by a user during a 15-minute time period.
SV-273190r1099763_ruleThe Okta Dashboard application must be configured to allow authentication only via non-phishable authenticators.
SV-273191r1099764_ruleThe Okta Admin Console application must be configured to allow authentication only via non-phishable authenticators.
SV-273192r1098843_ruleOkta must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the application.
SV-273193r1098846_ruleThe Okta Admin Console application must be configured to use multifactor authentication.
SV-273194r1098849_ruleThe Okta Dashboard application must be configured to use multifactor authentication.
SV-273195r1098852_ruleOkta must enforce a minimum 15-character password length.
SV-273196r1098855_ruleOkta must enforce password complexity by requiring that at least one uppercase character be used.
SV-273197r1098858_ruleOkta must enforce password complexity by requiring that at least one lowercase character be used.
SV-273198r1098861_ruleOkta must enforce password complexity by requiring that at least one numeric character be used.
SV-273199r1098864_ruleOkta must enforce password complexity by requiring that at least one special character be used.
SV-273200r1098867_ruleOkta must enforce 24 hours/one day as the minimum password lifetime.
SV-273201r1098870_ruleOkta must enforce a 60-day maximum password lifetime restriction.
SV-273202r1099766_ruleOkta must off-load audit records onto a central log server.
SV-273203r1099958_ruleOkta must be configured to limit the global session lifetime to 18 hours.
SV-273204r1098879_ruleOkta must be configured to accept Personal Identity Verification (PIV) credentials.
SV-273205r1098882_ruleThe Okta Verify application must be configured to connect only to FIPS-compliant devices.
SV-273206r1098885_ruleOkta must be configured to disable persistent global session cookies.
SV-273207r1098888_ruleOkta must be configured to use only DOD-approved certificate authorities.
SV-273208r1099769_ruleOkta must validate passwords against a list of commonly used, expected, or compromised passwords.
SV-273209r1098894_ruleOkta must prohibit password reuse for a minimum of five generations.
SV-279689r1155066_ruleOkta API tokens must be configured with Network Zones to restrict authorization from known networks.
SV-279690r1155069_ruleOkta API tokens must be created under new dedicated user accounts.
SV-279691r1155072_ruleThe Okta Global Session policy must be configured to allow or deny IP based access in accordance with the Access Control policy for Okta.
SV-279692r1155075_ruleOkta must be configured with Network Zones defined to block anonymized proxies according to organizationally defined policy.
SV-279693r1155078_ruleFor each application integrated with Okta, network zones must be defined in its authentication policy.