STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Tanium application must be configured for LDAP user/group synchronization to map the authenticated identity to the individual user or group account for PKI-based authentication.

DISA Rule

SV-254915r961044_rule

Vulnerability Number

V-254915

Group Title

SRG-APP-000177

Rule Version

TANS-AP-000490

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under "Configuration," select "LDAP/AD Sync Configurations".

4. Verify a sync exists under "Enabled Servers".

5. If no sync exists, click "Add Server".

6. Fill in the correct information for connecting to the organizations LDAP server. Work with a systems administrator to get this information if necessary.

7. Click "Save".

8. If a sync exists and it is disabled, click the edit icon.

9. Change the status to "enabled".

10. Click "Save".

Check Contents

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under "Configuration," select "LDAP/AD Sync Configurations".

4. Verify a sync exists under "Enabled Servers".

If no sync exists, this is a finding. If sync exists under "Disabled Servers" and there are no Enabled Servers, this is a finding."

Vulnerability Number

V-254915

Documentable

False

Rule Version

TANS-AP-000490

Severity Override Guidance

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under "Configuration," select "LDAP/AD Sync Configurations".

4. Verify a sync exists under "Enabled Servers".

If no sync exists, this is a finding. If sync exists under "Disabled Servers" and there are no Enabled Servers, this is a finding."

Check Content Reference

M

Target Key

5492