Okta identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On Okta, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Okta connector needs.
Checks (5)
severity: high Admin Without MFA fix difficulty: medium #
Require MFA for all Okta super-admins
- Navigate to Okta Admin > Security > Authenticators
- On the Setup tab, add Okta Verify or FIDO2 WebAuthn as authenticators
- Navigate to Okta Admin > Security > Authentication Policies
- Edit the admin policy rule to require MFA
- Verify affected admin users enroll in MFA
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high MFA Not Enrolled fix difficulty: medium #
Enroll all Okta users in MFA
- Navigate to Okta Admin > Security > Authenticators
- On the Enrollment tab, edit the authenticator enrollment policy
- Navigate to Okta Admin > Security > Authentication Policies
- Set required authenticators to Optional or Required for the target users
- Notify users to complete MFA enrollment
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Phishing Resistant MFA Factors fix difficulty: hard #
Enable phishing-resistant MFA factors and deprecate SMS and voice call authenticators
- Navigate to Okta Admin > Security > Authenticators
- On the Setup tab, add FIDO2 WebAuthn or Okta Verify FastPass as authenticators
- Deprecate SMS and voice call factors
- Update authentication policies to prefer phishing-resistant factors
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Session MFA Not Required fix difficulty: easy #
Require MFA for all Okta session establishment in authentication policies
- Navigate to Okta Admin > Security > Authentication Policies
- Select the relevant authentication policy
- Edit the policy rule to require MFA for session establishment
- Save changes
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Phishing Resistant Auth Policies fix difficulty: hard #
Update Okta authentication policies to require phishing-resistant factors such as FIDO2
- Navigate to Okta Admin > Security > Authentication Policies
- Edit each authentication policy rule
- Set the authentication constraint to require phishing-resistant factors (FIDO2/WebAuthn)
- Test the policy with a phishing-resistant authenticator
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4