STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the application.

DISA Rule

SV-251403r1004724_rule

Vulnerability Number

V-251403

Group Title

SRG-APP-000068-UEM-000037

Rule Version

IMIC-11-001500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the MDM server to display the appropriate warning banner text.

On the MDM console, do the following:
1. Log in to the MobileIron Core Server administrator portal as a user with the security configuration administrator role using a web browser.
2. Select Settings on the web page.
3. Select General on the web page.
4. Select Login on the web page.
5. Check the "Enable Login Text Box" on the web page.
6. Type the required banner text in the "Text to Display" dialog on the web page.
7. Select "Save" on the web page.

Check Contents

Review MDM server documentation and configuration settings to determine if the MDM server is using the warning banner and the wording of the banner is the required text.

On the MDM console, do the following:
1. Connect to the MobileIron Core Server using SSH.
2. Type in a user name and press enter.
3. Verify the required banner is displayed before the password prompt. The required text is found in the Vulnerability Discussion.
If the required banner is not presented, this is a finding.

1. Connect to the MobileIron Core Server system manager portal using a web browser.
2. Verify the required banner is displayed on the web page. The required text is found in the Vulnerability Discussion.
If the required banner is not presented, this is a finding.

1. Connect to the MobileIron Core Server administrator portal using a web browser.
2. Verify the required banner is displayed on the web page.
If the required banner is not presented, this is a finding.

Vulnerability Number

V-251403

Documentable

False

Rule Version

IMIC-11-001500

Severity Override Guidance

Review MDM server documentation and configuration settings to determine if the MDM server is using the warning banner and the wording of the banner is the required text.

On the MDM console, do the following:
1. Connect to the MobileIron Core Server using SSH.
2. Type in a user name and press enter.
3. Verify the required banner is displayed before the password prompt. The required text is found in the Vulnerability Discussion.
If the required banner is not presented, this is a finding.

1. Connect to the MobileIron Core Server system manager portal using a web browser.
2. Verify the required banner is displayed on the web page. The required text is found in the Vulnerability Discussion.
If the required banner is not presented, this is a finding.

1. Connect to the MobileIron Core Server administrator portal using a web browser.
2. Verify the required banner is displayed on the web page.
If the required banner is not presented, this is a finding.

Check Content Reference

M

Target Key

5445