STIGQter STIGQter: STIG Summary: NetApp ONTAP DSC 9.x Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

ONTAP must be configured to use an authentication server to provide multifactor authentication.

DISA Rule

SV-246940r1211037_rule

Vulnerability Number

V-246940

Group Title

SRG-APP-000516-NDM-000336

Rule Version

NAOT-CM-000002

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure ONTAP to use Active Directory to authenticate users and prohibit the use of cached authenticators with "security login create -user-or-group-name <user or group name> -authentication-method domain -application ssh".

Note: The authentication method "domain" is one example. Other authentication methods such as "publickey" and "saml" are also acceptable.

Check Contents

Use "security login show -authentication-method domain" to see users configured to authenticate with Active Directory.

If ONTAP is not configured to use an authentication server, this is a finding.

Note: The authentication method "domain" is one example. Other authentication methods such as "publickey" and "saml" are also acceptable.

Vulnerability Number

V-246940

Documentable

False

Rule Version

NAOT-CM-000002

Severity Override Guidance

Use "security login show -authentication-method domain" to see users configured to authenticate with Active Directory.

If ONTAP is not configured to use an authentication server, this is a finding.

Note: The authentication method "domain" is one example. Other authentication methods such as "publickey" and "saml" are also acceptable.

Check Content Reference

M

Target Key

5415