STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x ALG Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Sentry providing mobile device authentication intermediary services must restrict mobile device authentication traffic to specific authentication server(s).

DISA Rule

SV-251024r1028190_rule

Vulnerability Number

V-251024

Group Title

SRG-NET-000138-ALG-000089

Rule Version

MOIS-AL-000390

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If user authentication intermediary services are provided, configure the Sentry to use a specific authentication server(s).

For ActiveSync services:
1. In the MobileIron Core Admin Portal, go to Services >> Sentry.
2. Select Add New >> Standalone Sentry or click the "Edit" icon for an existing Standalone Sentry entry.
3. Complete the fields in the form for ActiveSync Configuration.
4. Configure approved ActiveSync servers.
5. Click "Save".

For AppTunnel services:
1. In the MobileIron Core Admin Portal, go to Services >> Sentry.
2. Select Add New >> Standalone Sentry or click the "Edit" icon for an existing Standalone Sentry entry.
3. Complete the fields in the form for AppTunnel Configuration.
4. Configure approved AppTunnel services.
5. Click "Save".

Check Contents

If the Sentry does not provide user authentication intermediary services, this is not applicable.

Verify the Sentry is configured with a preestablished trust relationship and mechanisms with appropriate authorities that validate each user access authorization and privileges.

If Sentry provides user authentication intermediary services for ActiveSync, verify them as follows:
1. In the MobileIron Core Admin Portal, go to Services >> Sentry.
2. Click the "Edit" icon next to Sentry, which opens the "Edit Standalone Sentry" dialog.
3. Determine if the fields in the form are configured for ActiveSync.
4. Look under "ActiveSync Server(s)".
5. Verify only the ActiveSync Servers' end users are on this list.

If ActiveSync Servers' end users are not the only entities on this list, this is a finding.

If Sentry provides user authentication intermediary services for AppTunnel, verify only the Servers that users should be authenticating to are specified in the Services list.

1. In the MobileIron Core Admin Portal, go to Services >> Sentry.
2. Select the "Edit" icon for an existing Standalone Sentry entry.
3. Review the Approved AppTunnel Services and verify only the Servers that users should be authenticating to are specified in the services list.

If end users are able to access AppTunnel services they should not be accessing, this is a finding.

Vulnerability Number

V-251024

Documentable

False

Rule Version

MOIS-AL-000390

Severity Override Guidance

If the Sentry does not provide user authentication intermediary services, this is not applicable.

Verify the Sentry is configured with a preestablished trust relationship and mechanisms with appropriate authorities that validate each user access authorization and privileges.

If Sentry provides user authentication intermediary services for ActiveSync, verify them as follows:
1. In the MobileIron Core Admin Portal, go to Services >> Sentry.
2. Click the "Edit" icon next to Sentry, which opens the "Edit Standalone Sentry" dialog.
3. Determine if the fields in the form are configured for ActiveSync.
4. Look under "ActiveSync Server(s)".
5. Verify only the ActiveSync Servers' end users are on this list.

If ActiveSync Servers' end users are not the only entities on this list, this is a finding.

If Sentry provides user authentication intermediary services for AppTunnel, verify only the Servers that users should be authenticating to are specified in the Services list.

1. In the MobileIron Core Admin Portal, go to Services >> Sentry.
2. Select the "Edit" icon for an existing Standalone Sentry entry.
3. Review the Approved AppTunnel Services and verify only the Servers that users should be authenticating to are specified in the services list.

If end users are able to access AppTunnel services they should not be accessing, this is a finding.

Check Content Reference

M

Target Key

5439