Key takeaways

Okta provides FIPS-compliant cryptographic modules for US government environments, including FedRAMP Moderate, FedRAMP High, and US Military (IL4/IL5) offerings.

Okta relies on validated CMVP modules across its agents, load balancers, and verification apps.

While Okta doesn’t offer full FIPS coverage in standard commercial environments, select commercial services have been assessed by 3PAO auditors and approved by agency sponsors as FIPS-compliant.

What is FIPS and how does Okta implement it?

Federal Information Processing Standards (FIPS) are security standards developed by the National Institute of Standards and Technology (NIST). To achieve FIPS compliance, a system or product must meet configuration standards and pass rigorous audits conducted by accredited third-party assessment organizations (3PAOs).

We often receive questions about FedRAMP High vs. FedRAMP Moderate, use in EPCS, and even about FIPS in our commercial service offerings. You can find full FIPS compliance details in our System Security Plans for both our FedRAMP Moderate and FedRAMP High service offerings. However, because these documents are about 500 pages long and must adhere to the FedRAMP template, finding the specific information you need quickly can be difficult.

This guide provides a direct, searchable breakdown of how and where FIPS is implemented across all Okta service environments.

Does Okta support FIPS compliance in commercial environments?

Okta does not support full FIPS coverage in its commercial cells. 

However, the specific Okta service offerings detailed in this guide have been assessed by our 3PAO and approved by our US government agency sponsors as meeting the required security standards and are considered FIPS compliant.

Which on-premises Okta software is FIPS compliant?

On-premises software is typically within customer security boundaries rather than Okta’s authorization boundaries. Okta supports customer compliance by often providing the following Cryptographic Module Validation Program (CMVP) certificates for our on-premises software:

Service

Port

CMVP Certificate

Okta Access Gateway

443

#4215, #4847

Okta Active Directory Agent

 

Customer responsibility to patch and ensure compliant version of Windows Cryptographic Primitives Library

Okta LDAP Agent

 

#2768

RADIUS

1812

#4743

Okta for Government Moderate (FedRAMP Moderate) FIPS compliance

The following ports and services within Okta for Government Moderate have been assessed as FIPS compliant:

Service

Port

CMVP Certificate

SAML
OIDC
APIs

443

#4884

SAML OIDC APIs - AWS ALB and ELBs

443

#4631

Password storage in Universal Directory

 

#4743

Custom Domains

443

#5021

CDN (Cloudfront)

443

#4884

Okta Verify iOS

443

#5306, #5307

Okta Verify Android

443

#4718

Okta Verify MacOS

 

Customer responsibility to patch and ensure compliant version of CoreCrypto

Okta Verify Windows

 

Customer responsibility to patch and ensure compliant version of Windows Cryptographic Primitives Library

Okta Identity Governance Inbox

 #4856

Okta Identity Governance Inbox - SAML, OIDC, APIs - AWS ALB and ELBs

 #4631

Okta Workflows - SAML, OIDC, APIs - AWS ALB and ELBs

 #4631

Amazon EBS

 #4884

Okta for Government High (FedRAMP High) FIPS compliance

The following ports and services within Okta for Government High have been assessed as FIPS compliant:

Service

Port

CMVP Certificate

SAML
OIDC
APIs

443

#4884

SAML OIDC APIs - AWS ALB and ELBs

443

#4631

Password storage in Universal Directory

 

#4743

Custom Domains

443

#5021

CDN (Cloudfront)

443

#4884

Okta Verify iOS

443

#5306, #5307

Okta Verify Android

443

#4718

Okta Verify MacOS

 

Customer responsibility to patch and ensure compliant version of CoreCrypto

Okta Verify Windows

 

Customer responsibility to patch and ensure compliant version of Windows Cryptographic Primitives Library

DNS (DNSSec)

53

#4535

Okta LDAP Agent

 

#4743

Okta Identity Governance Inbox

 #4856

Okta Identity Governance Inbox - SAML, OIDC, APIs - AWS ALB and ELBs

 

#4631

Okta Workflows - SAML, OIDC, APIs - AWS ALB and ELBs

 

#4631

Amazon EBS

 

#4884

Okta for US Military (IL4 with approval for IL5 workloads) FIPS compliance

The following ports and services within Okta for US Military Department of Defense (DoD) Impact Level 4 and 5 (IL4/IL5) environments have been assessed as FIPS compliant:

Service

Port

CMVP Certificate

SAML
OIDC
APIs

443

#4884

SAML OIDC APIs - AWS ALB and ELBs

443

#4631

Password storage in Universal Directory

 

#4743

Custom Domains

443

#5021

CDN (Cloudfront)

443

#4884

Okta Verify iOS

443

#5306, #5307

Okta Verify Android

443

#4718

Okta Verify MacOS

 

Customer responsibility to patch and ensure compliant version of CoreCrypto

Okta Verify Windows

 

Customer responsibility to patch and ensure compliant version of Windows Cryptographic Primitives Library

DNS (DNSSec)

53

#4535

Okta LDAP Agent

 

#4743

Okta Identity Governance Inbox

 

#4856

Okta Identity Governance Inbox - SAML, OIDC, APIs - AWS ALB and ELBs

 

#4631

Okta Workflows - SAML, OIDC, APIs - AWS ALB and ELBs

 

#4631

Amazon EBS

 

#4884

Multi-factor authentication (MFA)

 #3907, #4357

Post-quantum cryptography

Without regular updates, cryptographic security will suffer from the advent of faster and more efficient computers. As a result, Okta looks forward to NIST’s approval of new algorithms to mitigate these emerging privacy risks. 

How to configure FIPS programmatically with Okta API

Administrators can use the Okta Features API to automate their FIPS settings configuration in Okta, and to view all features and modify the FIPS setting or ID name.

Example: Checking FIPS status with the Okta Features API

Here is an example of the FIPS control output:

“id”: “ftrc96y7bJh7DG2k6tJW”,
“type”: “self-service”,
“status”: “ENABLED”,
“name”:  “FIPS compliance”,
“description”: “This feature allows you to configure FIPS compliance on iOS or
Android devices that enroll in Okta Verify.”, ….

Enable FIPS for specific Okta features

Once you’ve enabled FIPS capabilities within your Okta tenant using the API or Admin Console, complete your deployment setup using our step-by-step guides to enable FIPS compliance across specific components:

Need assistance with federal compliance? 

We hope that this guide saves our customers time when searching for details about Okta’s FIPS compliance. We also expect this guide to assist US government agencies with their own compliance requirements. 

If you have any further questions about Okta’s FIPS-compliant products and services, contact us at federal@okta.com.

Continue your Identity journey