STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x ALG Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Sentry must enforce approved authorizations for logical access to information and system resources by enabling identity-based, role-based, and/or attribute-based security policies. These controls are enabled in MobileIron UEM (MobileIron Core) and applied by the Sentry for conditional access enforcement.

DISA Rule

SV-251008r1028171_rule

Vulnerability Number

V-251008

Group Title

SRG-NET-000015-ALG-000016

Rule Version

MOIS-AL-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Sentry to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies.

1. Log in to the Core Admin Portal.
2. Go to Services >> Sentry.
3. Create one or all of the applicable Sentry Services: ActiveSync, AppTunnel, or Kerberos Proxy based on the Sentry use case. (Refer to the Sentry Guide on how to configure the specific Sentry Services. ActiveSync: Page 43; AppTunnel: Page 64; Kerberos Proxy: Page 92.)
4. If Sentry is being used as an ActiveSync Proxy or AppTunnel, configure an Identity Certificate for the Device Authentication Configuration in the Sentry Configuration and enable the CRL checkbox.
5. Save the Sentry configuration.

MobileIron UEM applies security, privacy, lockdown, and sync policies to registered devices. These policies ensure that devices can connect only if they comply to an organization’s security requirements. Standalone Sentry gets device posture and compliance information from MobileIron UEM and allows access to email via ActiveSync or backend systems based on the device posture.

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Policies.
3. Create or edit the Lockdown and Security Policies.
4. Ensure the policies are applied to devices accessing systems behind a Sentry if configuring Sentry for ActiveSync.

By default, Sentry allows unregistered devices to access the ActiveSync server. Use this setting to change Sentry’s behavior to block unregistered devices from access if configuring Sentry for ActiveSync.

1. Log in to the Core Admin Portal.
2. Go to Services >> Sentry >> Preferences.
3. Change the Auto Block Unregistered Devices setting to "Yes".
4. Click "Save".

Check Contents

Verify the Sentry is configured to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and attribute-based security policies. The Sentry system configured for ActiveSync, AppTunnel, and/or as a Kerberos Proxy ensures only authenticated and authorized apps and managed devices have access to backend resources. Refer to the Sentry 9.8.0 Guide for Core pages 20-21 for more information.

1. Log in to the Core Admin Portal.
2. Go to Service >> Sentry.
3. Verify the Sentry is configured with one or all the of the applicable services (ActiveSync, AppTunnel, or Kerberos Proxy). If no services are applied, this is a finding.
4. If Sentry is being used as an ActiveSync Proxy or AppTunnel, verify an Identity Certificate is configured for the Device Authentication Configuration in the Sentry Configuration and that CRL is enabled. If not, this is a finding.

Refer to the Sentry 9.8.0 Guide on how to configure the specific Sentry Services. ActiveSync: Standalone Sentry for ActiveSync Email Section, AppTunnel: Standalone Sentry for AppTunnel Section Kerberos Proxy: Standalone Sentry for KKDCP Section.

MobileIron UEM applies security, privacy, lockdown, and sync policies to registered devices. These policies ensure that devices can connect only if they comply to an organization’s security requirements. Standalone Sentry gets device posture and compliance information from MobileIron UEM, and allows access to Email via ActiveSync or backend systems based on the device posture.

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Policies.
3. Verify the appropriate Lockdown and Security Policies are applied to the devices accessing systems behind the Sentry.

If no policies are applied, this is a finding.

By default, Sentry allows unregistered devices to access the ActiveSync server. Use this setting to change Sentry’s behavior to block unregistered devices from access if configuring Sentry for ActiveSync.

1. Log in to the Core Admin Portal.
2. Go to Services >> Sentry >> Preferences.
3. Verify "Yes" for Auto Block Unregistered Devices is applied.

If not applied, this is a finding.

Vulnerability Number

V-251008

Documentable

False

Rule Version

MOIS-AL-000010

Severity Override Guidance

Verify the Sentry is configured to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and attribute-based security policies. The Sentry system configured for ActiveSync, AppTunnel, and/or as a Kerberos Proxy ensures only authenticated and authorized apps and managed devices have access to backend resources. Refer to the Sentry 9.8.0 Guide for Core pages 20-21 for more information.

1. Log in to the Core Admin Portal.
2. Go to Service >> Sentry.
3. Verify the Sentry is configured with one or all the of the applicable services (ActiveSync, AppTunnel, or Kerberos Proxy). If no services are applied, this is a finding.
4. If Sentry is being used as an ActiveSync Proxy or AppTunnel, verify an Identity Certificate is configured for the Device Authentication Configuration in the Sentry Configuration and that CRL is enabled. If not, this is a finding.

Refer to the Sentry 9.8.0 Guide on how to configure the specific Sentry Services. ActiveSync: Standalone Sentry for ActiveSync Email Section, AppTunnel: Standalone Sentry for AppTunnel Section Kerberos Proxy: Standalone Sentry for KKDCP Section.

MobileIron UEM applies security, privacy, lockdown, and sync policies to registered devices. These policies ensure that devices can connect only if they comply to an organization’s security requirements. Standalone Sentry gets device posture and compliance information from MobileIron UEM, and allows access to Email via ActiveSync or backend systems based on the device posture.

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Policies.
3. Verify the appropriate Lockdown and Security Policies are applied to the devices accessing systems behind the Sentry.

If no policies are applied, this is a finding.

By default, Sentry allows unregistered devices to access the ActiveSync server. Use this setting to change Sentry’s behavior to block unregistered devices from access if configuring Sentry for ActiveSync.

1. Log in to the Core Admin Portal.
2. Go to Services >> Sentry >> Preferences.
3. Verify "Yes" for Auto Block Unregistered Devices is applied.

If not applied, this is a finding.

Check Content Reference

M

Target Key

5439