Skip to content

Okta identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Okta, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Okta connector needs.

Checks (5)

severity: high Admin Without MFA fix difficulty: medium #

Require MFA for all Okta super-admins

  1. Navigate to Okta Admin > Security > Authenticators
  2. On the Setup tab, add Okta Verify or FIDO2 WebAuthn as authenticators
  3. Navigate to Okta Admin > Security > Authentication Policies
  4. Edit the admin policy rule to require MFA
  5. Verify affected admin users enroll in MFA

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high MFA Not Enrolled fix difficulty: medium #

Enroll all Okta users in MFA

  1. Navigate to Okta Admin > Security > Authenticators
  2. On the Enrollment tab, edit the authenticator enrollment policy
  3. Navigate to Okta Admin > Security > Authentication Policies
  4. Set required authenticators to Optional or Required for the target users
  5. Notify users to complete MFA enrollment

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Phishing Resistant MFA Factors fix difficulty: hard #

Enable phishing-resistant MFA factors and deprecate SMS and voice call authenticators

  1. Navigate to Okta Admin > Security > Authenticators
  2. On the Setup tab, add FIDO2 WebAuthn or Okta Verify FastPass as authenticators
  3. Deprecate SMS and voice call factors
  4. Update authentication policies to prefer phishing-resistant factors

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Session MFA Not Required fix difficulty: easy #

Require MFA for all Okta session establishment in authentication policies

  1. Navigate to Okta Admin > Security > Authentication Policies
  2. Select the relevant authentication policy
  3. Edit the policy rule to require MFA for session establishment
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Phishing Resistant Auth Policies fix difficulty: hard #

Update Okta authentication policies to require phishing-resistant factors such as FIDO2

  1. Navigate to Okta Admin > Security > Authentication Policies
  2. Edit each authentication policy rule
  3. Set the authentication constraint to require phishing-resistant factors (FIDO2/WebAuthn)
  4. Test the policy with a phishing-resistant authenticator

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

More Okta checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial