Skip to content

Okta configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Okta, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Okta connector needs.

Checks (7)

severity: medium Password Policy No Symbol Requirement fix difficulty: easy #

Update the Okta password policy to require at least one symbol character

  1. Navigate to Okta Admin > Security > Authentication > Password
  2. Select the password policy to edit
  3. Under complexity requirements, set the minimum symbol count to at least 1
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Password Policy No Username Exclusion fix difficulty: easy #

Enable username exclusion in the Okta password policy to prevent users from using their username as a password

  1. Navigate to Okta Admin > Security > Authentication > Password
  2. Select the password policy to edit
  3. Under complexity requirements, enable the exclude username option
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Account Lockout Auto-Unlock Too Fast fix difficulty: easy #

Increase the Okta account lockout duration to at least 15 minutes to slow brute-force attacks

  1. Navigate to Okta Admin > Security > Authentication > Password
  2. Select the password policy to edit
  3. Under lockout settings, set the auto-unlock duration to at least 15 minutes
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Inactive Application fix difficulty: easy #

Delete inactive Okta applications to reduce attack surface and simplify the application portfolio

  1. Navigate to Okta Admin > Applications > Applications
  2. Filter by status to find inactive applications
  3. Review each inactive application to confirm it is no longer needed
  4. Delete applications that are confirmed as unnecessary
  5. Document the removal decision for compliance records

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium ThreatInsight Not Blocking fix difficulty: easy #

Set Okta ThreatInsight to block sign-in attempts from malicious IPs

  1. Navigate to Okta Admin > Security > General
  2. Under Okta ThreatInsight settings, select "Log and block sign-in attempts"
  3. Save the change

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low ThreatInsight Excluded Zones fix difficulty: easy #

Remove network zones excluded from Okta ThreatInsight protection

  1. Navigate to Okta Admin > Security > General
  2. Under Okta ThreatInsight settings, review the excluded zones list
  3. Remove zones that do not have a documented business justification

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Anonymizer Block Absent fix difficulty: medium #

Create an active blocklist network zone for anonymizing proxies

  1. Navigate to Okta Admin > Security > Networks
  2. Add a Dynamic Zone with proxy type Tor or a Dynamic Zone v2 covering anonymizers
  3. Set the zone usage to blocklist and activate it

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Okta checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial