STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Tanium Application Server must be configured to only use LDAP for account management functions.

DISA Rule

SV-254881r1043176_rule

Vulnerability Number

V-254881

Group Title

SRG-APP-000023

Rule Version

TANS-AP-000065

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Vendor documentation can be downloaded from the following URL: https://docs.tanium.com/platform_user/platform_user/console_using_ldap.html?Highlight=LDAP

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under "Configuration," select "LDAP/AD Sync Configurations".

4. Follow the vendor documentation titled "Integrating with LDAP Servers" to implement correct configuration settings for this requirement.

Check Contents

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under "Configuration," select "LDAP/AD Sync Configurations".

4. Ensure LDAP sync is enabled.

If LDAP is not enabled, this is a finding.

Vulnerability Number

V-254881

Documentable

False

Rule Version

TANS-AP-000065

Severity Override Guidance

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under "Configuration," select "LDAP/AD Sync Configurations".

4. Ensure LDAP sync is enabled.

If LDAP is not enabled, this is a finding.

Check Content Reference

M

Target Key

5492