STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

DISA Rule

SV-251402r1004723_rule

Vulnerability Number

V-251402

Group Title

SRG-APP-000065-UEM-000036

Rule Version

IMIC-11-001400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Ivanti EPMM server to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

Go to Settings >> Security >> Password Policy. Set Number of Failed attempts to 3 and set Auto-Lock Time to 900 seconds.

Check Contents

Verify the Ivanti EPMM server is configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

In the Core server, navigate to the following: Settings >> Security >> Password Policy.

Verify the number of failed attempts is set to 3 and Auto-Lock Time is set to 900 seconds.

If the number of failed attempts is not set to 3 and Auto-Lock Time is not set to 900 seconds, this is a finding.

Vulnerability Number

V-251402

Documentable

False

Rule Version

IMIC-11-001400

Severity Override Guidance

Verify the Ivanti EPMM server is configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

In the Core server, navigate to the following: Settings >> Security >> Password Policy.

Verify the number of failed attempts is set to 3 and Auto-Lock Time is set to 900 seconds.

If the number of failed attempts is not set to 3 and Auto-Lock Time is not set to 900 seconds, this is a finding.

Check Content Reference

M

Target Key

5445