STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x ALG Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Sentry providing mobile device access control intermediary services must be configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or AAA server) which validate mobile device account access authorizations and privileges.

DISA Rule

SV-251023r1028189_rule

Vulnerability Number

V-251023

Group Title

SRG-NET-000138-ALG-000088

Rule Version

MOIS-AL-000380

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure the MobileIron Core configured with the Sentry is enabled with Active Directory or LDAP server.

1. Log in to the MobileIron Core MIFS portal.
2. Go to Services >> LDAP.
3. Click "Add New".
4. Follow LDAP Configuration Wizard Prompts to enable an LDAP server (refer to the "Configuring LDAP Servers" section of the "Getting Started with MobileIron Core Guide" for more information).
5. Click "Save".

Check Contents

Verify the MobileIron Core configured with the Sentry is enabled with Active Directory or LDAP server.

1. Log in to the MobileIron Core MIFS portal.
2. Go to Services >> LDAP.
3. Verify an LDAP server is configured and enabled.

If an LDAP server is not configured and enabled, this is a finding.

Vulnerability Number

V-251023

Documentable

False

Rule Version

MOIS-AL-000380

Severity Override Guidance

Verify the MobileIron Core configured with the Sentry is enabled with Active Directory or LDAP server.

1. Log in to the MobileIron Core MIFS portal.
2. Go to Services >> LDAP.
3. Verify an LDAP server is configured and enabled.

If an LDAP server is not configured and enabled, this is a finding.

Check Content Reference

M

Target Key

5439