STIGQter STIGQter: STIG Summary: Microsoft SharePoint 2013 Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

SharePoint must use replay-resistant authentication mechanisms for network access to privileged accounts.

DISA Rule

SV-223250r612235_rule

Vulnerability Number

V-223250

Group Title

SRG-APP-000156

Rule Version

SP13-00-000075

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the SharePoint server to use replay-resistant authentication mechanisms for network access to privileged accounts.

If the web application is using Integrated Windows Authentication as the claims provider, perform the following:

Open the Central Administration site, select "Application Management".

On the "Application Management" page, select "Manage Web Applications", select the web application that corresponds to the site reviewed in the "Check" section above, then click the "Authentication Providers" button in the ribbon.

Select the zone corresponding to the web application being reviewed, which will open the "Edit Authentication" dialog in the "Claims Authentication Types" section, select "Negotiate (Kerberos)" in the "Integrated Windows Authentication" dropdown, then click "Save".

Check Contents

Review the SharePoint server configuration to ensure replay-resistant authentication mechanisms for network access to privileged accounts are used.

SharePoint must be configured to use Kerberos as the primary authentication provider.

Log on to the server.

Click Start.

Type Internet Information Services Manager in the Search Bar, click Enter.

Expand the server node in the tree view and expand the "Sites" node.

*For each...* Select a SharePoint Web Application site to review.

In the "IIS" section, double-click Authentication and then select "Windows Authentication".

Right-click "Windows Authentication" and select "Providers".

Ensure "Negotiate" is listed first. If NTLM is listed first in the Enabled Providers box, this is a finding.

Vulnerability Number

V-223250

Documentable

False

Rule Version

SP13-00-000075

Severity Override Guidance

Review the SharePoint server configuration to ensure replay-resistant authentication mechanisms for network access to privileged accounts are used.

SharePoint must be configured to use Kerberos as the primary authentication provider.

Log on to the server.

Click Start.

Type Internet Information Services Manager in the Search Bar, click Enter.

Expand the server node in the tree view and expand the "Sites" node.

*For each...* Select a SharePoint Web Application site to review.

In the "IIS" section, double-click Authentication and then select "Windows Authentication".

Right-click "Windows Authentication" and select "Providers".

Ensure "Negotiate" is listed first. If NTLM is listed first in the Enabled Providers box, this is a finding.

Check Content Reference

M

Target Key

4096

Comments