STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must configured to lock administrator accounts after three unsuccessful login attempts.

DISA Rule

SV-251774r1004738_rule

Vulnerability Number

V-251774

Group Title

SRG-APP-000345-UEM-000218

Rule Version

IMIC-11-008510

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Ivanti EPMM server to lock administrator accounts after three unsuccessful login attempts.

Log in to the Core Admin Console >> Settings >> Security >> Password Policy.
Set "Number of Failed attempts" to "3".

Check Contents

Verify the Ivanti EPMM server has been configured to lock administrator accounts after three unsuccessful login attempts.

Log in to the Core Admin Console >> Settings >> Security >> Password Policy.
Verify "Number of Failed attempts" is set to "3".

If the Ivanti EPMM server does not lock administrator accounts after three unsuccessful login attempts, this is a finding.

Vulnerability Number

V-251774

Documentable

False

Rule Version

IMIC-11-008510

Severity Override Guidance

Verify the Ivanti EPMM server has been configured to lock administrator accounts after three unsuccessful login attempts.

Log in to the Core Admin Console >> Settings >> Security >> Password Policy.
Verify "Number of Failed attempts" is set to "3".

If the Ivanti EPMM server does not lock administrator accounts after three unsuccessful login attempts, this is a finding.

Check Content Reference

M

Target Key

5445