Key takeaways
Okta provides FIPS-compliant cryptographic modules for US government environments, including FedRAMP Moderate, FedRAMP High, and US Military (IL4/IL5) offerings.
Okta relies on validated CMVP modules across its agents, load balancers, and verification apps.
While Okta doesn’t offer full FIPS coverage in standard commercial environments, select commercial services have been assessed by 3PAO auditors and approved by agency sponsors as FIPS-compliant.
What is FIPS and how does Okta implement it?
Federal Information Processing Standards (FIPS) are security standards developed by the National Institute of Standards and Technology (NIST). To achieve FIPS compliance, a system or product must meet configuration standards and pass rigorous audits conducted by accredited third-party assessment organizations (3PAOs).
We often receive questions about FedRAMP High vs. FedRAMP Moderate, use in EPCS, and even about FIPS in our commercial service offerings. You can find full FIPS compliance details in our System Security Plans for both our FedRAMP Moderate and FedRAMP High service offerings. However, because these documents are about 500 pages long and must adhere to the FedRAMP template, finding the specific information you need quickly can be difficult.
This guide provides a direct, searchable breakdown of how and where FIPS is implemented across all Okta service environments.
Does Okta support FIPS compliance in commercial environments?
Okta does not support full FIPS coverage in its commercial cells.
However, the specific Okta service offerings detailed in this guide have been assessed by our 3PAO and approved by our US government agency sponsors as meeting the required security standards and are considered FIPS compliant.
Which on-premises Okta software is FIPS compliant?
On-premises software is typically within customer security boundaries rather than Okta’s authorization boundaries. Okta supports customer compliance by often providing the following Cryptographic Module Validation Program (CMVP) certificates for our on-premises software:
Service | Port | CMVP Certificate |
Okta Access Gateway | 443 | #4215, #4847 |
Okta Active Directory Agent | Customer responsibility to patch and ensure compliant version of Windows Cryptographic Primitives Library | |
Okta LDAP Agent | #2768 | |
RADIUS | 1812 | #4743 |
Okta for Government Moderate (FedRAMP Moderate) FIPS compliance
The following ports and services within Okta for Government Moderate have been assessed as FIPS compliant:
Service | Port | CMVP Certificate |
SAML | 443 | |
SAML OIDC APIs - AWS ALB and ELBs | 443 | #4631 |
Password storage in Universal Directory |
| #4743 |
Custom Domains | 443 | |
CDN (Cloudfront) | 443 | |
Okta Verify iOS | 443 | #5306, #5307 |
Okta Verify Android | 443 | |
Okta Verify MacOS | Customer responsibility to patch and ensure compliant version of CoreCrypto | |
Okta Verify Windows | Customer responsibility to patch and ensure compliant version of Windows Cryptographic Primitives Library | |
Okta Identity Governance Inbox | #4856 | |
Okta Identity Governance Inbox - SAML, OIDC, APIs - AWS ALB and ELBs | #4631 | |
Okta Workflows - SAML, OIDC, APIs - AWS ALB and ELBs | #4631 | |
Amazon EBS | #4884 |
Okta for Government High (FedRAMP High) FIPS compliance
The following ports and services within Okta for Government High have been assessed as FIPS compliant:
Service | Port | CMVP Certificate |
SAML | 443 | #4884 |
SAML OIDC APIs - AWS ALB and ELBs | 443 | #4631 |
Password storage in Universal Directory |
| #4743 |
Custom Domains | 443 | #5021 |
CDN (Cloudfront) | 443 | #4884 |
Okta Verify iOS | 443 | #5306, #5307 |
Okta Verify Android | 443 | #4718 |
Okta Verify MacOS | Customer responsibility to patch and ensure compliant version of CoreCrypto | |
Okta Verify Windows | Customer responsibility to patch and ensure compliant version of Windows Cryptographic Primitives Library | |
DNS (DNSSec) | 53 | #4535 |
Okta LDAP Agent | #4743 | |
Okta Identity Governance Inbox | #4856 | |
Okta Identity Governance Inbox - SAML, OIDC, APIs - AWS ALB and ELBs | #4631 | |
Okta Workflows - SAML, OIDC, APIs - AWS ALB and ELBs | #4631 | |
Amazon EBS |
Okta for US Military (IL4 with approval for IL5 workloads) FIPS compliance
The following ports and services within Okta for US Military Department of Defense (DoD) Impact Level 4 and 5 (IL4/IL5) environments have been assessed as FIPS compliant:
Service | Port | CMVP Certificate |
SAML | 443 | |
SAML OIDC APIs - AWS ALB and ELBs | 443 | #4631 |
Password storage in Universal Directory | #4743 | |
Custom Domains | 443 | |
CDN (Cloudfront) | 443 | |
Okta Verify iOS | 443 | #5306, #5307 |
Okta Verify Android | 443 | |
Okta Verify MacOS | Customer responsibility to patch and ensure compliant version of CoreCrypto | |
Okta Verify Windows | Customer responsibility to patch and ensure compliant version of Windows Cryptographic Primitives Library | |
DNS (DNSSec) | 53 | #4535 |
Okta LDAP Agent | #4743 | |
Okta Identity Governance Inbox | #4856 | |
Okta Identity Governance Inbox - SAML, OIDC, APIs - AWS ALB and ELBs | #4631 | |
Okta Workflows - SAML, OIDC, APIs - AWS ALB and ELBs | #4631 | |
Amazon EBS | ||
Multi-factor authentication (MFA) | #3907, #4357 |
Post-quantum cryptography
Without regular updates, cryptographic security will suffer from the advent of faster and more efficient computers. As a result, Okta looks forward to NIST’s approval of new algorithms to mitigate these emerging privacy risks.
How to configure FIPS programmatically with Okta API
Administrators can use the Okta Features API to automate their FIPS settings configuration in Okta, and to view all features and modify the FIPS setting or ID name.
Example: Checking FIPS status with the Okta Features API
Here is an example of the FIPS control output:
“id”: “ftrc96y7bJh7DG2k6tJW”, “type”: “self-service”, “status”: “ENABLED”, “name”: “FIPS compliance”, “description”: “This feature allows you to configure FIPS compliance on iOS or Android devices that enroll in Okta Verify.”, ….
Enable FIPS for specific Okta features
Once you’ve enabled FIPS capabilities within your Okta tenant using the API or Admin Console, complete your deployment setup using our step-by-step guides to enable FIPS compliance across specific components:
Okta Verify: Learn how to enable FIPS encryption on Okta Verify to enforce device-level FIPS encryption in the Okta Admin Console
Okta Access Gateway: See how to enable FIPS mode to configure cryptographic protection directly on your on-premises servers.
Need assistance with federal compliance?
We hope that this guide saves our customers time when searching for details about Okta’s FIPS compliance. We also expect this guide to assist US government agencies with their own compliance requirements.
If you have any further questions about Okta’s FIPS-compliant products and services, contact us at federal@okta.com.