STIGQter STIGQter: STIG Summary: Red Hat Ansible Automation Controller Application Server Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 05 Jan 2026:

Automation Controller must be configured to authenticate users individually, prior to using a group authenticator.

DISA Rule

SV-256906r1015790_rule

Vulnerability Number

V-256906

Group Title

SRG-APP-000153-AS-000104

Rule Version

APAS-AT-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the Automation Controller web console as an administrator and navigate to Access >> Users.

Click the Username to be removed.

Select "Delete" and confirm.

Check Contents

Log in to the Automation Controller web console as an administrator and navigate to Access >> Users.

The only local user allowed is the default/breakglass "admin". All other users need to come from an external authentication source. If any other local users exist, this is a finding.

Vulnerability Number

V-256906

Documentable

False

Rule Version

APAS-AT-000050

Severity Override Guidance

Log in to the Automation Controller web console as an administrator and navigate to Access >> Users.

The only local user allowed is the default/breakglass "admin". All other users need to come from an external authentication source. If any other local users exist, this is a finding.

Check Content Reference

M

Target Key

5534