STIGQter STIGQter: STIG Summary: Samsung SDS EMM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 27 Jul 2022:

The Samsung SDS EMM server must be configured to use one-time password in addition to username and password for administrator logon to the server.

DISA Rule

SV-225649r744410_rule

Vulnerability Number

V-225649

Group Title

PP-MDM-414003

Rule Version

SSDS-00-000725

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Use the following procedure for configuring the use of OTP authentication on the EMM server:

On the MDM console, do the following:
1. Log into the SDS EMM console.
2. Go to Setting >> Server >> Configuration >> Two-Factor Authentication.
3. Set Two-Factor Authentication to "No".
4. Save setting.

Check Contents

Verify the EMM server has not been configured to use one-time password (OTP) for administrator logon to the server.

On the MDM console, do the following:
1. Log into the SDS EMM console.
2. Go to Setting >> Server >> Configuration >> Two-Factor Authentication.
3. Verify Two-Factor Authentication is set to "No".

If the EMM server has not been configured to disable one-time-password (OTP) for administrator logon to the server, this is a finding.

Vulnerability Number

V-225649

Documentable

False

Rule Version

SSDS-00-000725

Severity Override Guidance

Verify the EMM server has not been configured to use one-time password (OTP) for administrator logon to the server.

On the MDM console, do the following:
1. Log into the SDS EMM console.
2. Go to Setting >> Server >> Configuration >> Two-Factor Authentication.
3. Verify Two-Factor Authentication is set to "No".

If the EMM server has not been configured to disable one-time-password (OTP) for administrator logon to the server, this is a finding.

Check Content Reference

M

Target Key

4216