STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must prohibit password reuse for a minimum of four generations.

DISA Rule

SV-251408r1004729_rule

Vulnerability Number

V-251408

Group Title

SRG-APP-000165-UEM-000095

Rule Version

IMIC-11-004950

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Core to enforce password history reuse of four last passwords:

1. Log in to the Core console.
2. Security >> Password Policy.
3. Check "Enable" for "Enforce Password History (Last 4 passwords)".

Check Contents

Verify Core is configured to enforce password history reuse of four last passwords:

1. Log in to the Core console.
2. Security >> Password Policy.
3. Verify "Enforce Password History (Last 4 passwords)" is enabled.

If "Enforce Password History (Last 4 passwords)" is not enabled, this is a finding.

Vulnerability Number

V-251408

Documentable

False

Rule Version

IMIC-11-004950

Severity Override Guidance

Verify Core is configured to enforce password history reuse of four last passwords:

1. Log in to the Core console.
2. Security >> Password Policy.
3. Verify "Enforce Password History (Last 4 passwords)" is enabled.

If "Enforce Password History (Last 4 passwords)" is not enabled, this is a finding.

Check Content Reference

M

Target Key

5445