Okta configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Okta, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Okta connector needs.
Checks (7)
severity: medium Password Policy No Symbol Requirement fix difficulty: easy #
Update the Okta password policy to require at least one symbol character
- Navigate to Okta Admin > Security > Authentication > Password
- Select the password policy to edit
- Under complexity requirements, set the minimum symbol count to at least 1
- Save changes
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Password Policy No Username Exclusion fix difficulty: easy #
Enable username exclusion in the Okta password policy to prevent users from using their username as a password
- Navigate to Okta Admin > Security > Authentication > Password
- Select the password policy to edit
- Under complexity requirements, enable the exclude username option
- Save changes
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Account Lockout Auto-Unlock Too Fast fix difficulty: easy #
Increase the Okta account lockout duration to at least 15 minutes to slow brute-force attacks
- Navigate to Okta Admin > Security > Authentication > Password
- Select the password policy to edit
- Under lockout settings, set the auto-unlock duration to at least 15 minutes
- Save changes
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Inactive Application fix difficulty: easy #
Delete inactive Okta applications to reduce attack surface and simplify the application portfolio
- Navigate to Okta Admin > Applications > Applications
- Filter by status to find inactive applications
- Review each inactive application to confirm it is no longer needed
- Delete applications that are confirmed as unnecessary
- Document the removal decision for compliance records
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium ThreatInsight Not Blocking fix difficulty: easy #
Set Okta ThreatInsight to block sign-in attempts from malicious IPs
- Navigate to Okta Admin > Security > General
- Under Okta ThreatInsight settings, select "Log and block sign-in attempts"
- Save the change
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low ThreatInsight Excluded Zones fix difficulty: easy #
Remove network zones excluded from Okta ThreatInsight protection
- Navigate to Okta Admin > Security > General
- Under Okta ThreatInsight settings, review the excluded zones list
- Remove zones that do not have a documented business justification
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Anonymizer Block Absent fix difficulty: medium #
Create an active blocklist network zone for anonymizing proxies
- Navigate to Okta Admin > Security > Networks
- Add a Dynamic Zone with proxy type Tor or a Dynamic Zone v2 covering anonymizers
- Set the zone usage to blocklist and activate it
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10