STIGQter STIGQter: STIG Summary: Unified Endpoint Management Server Security Requirements Guide Version: 2 Release: 5 Benchmark Date: 29 Jun 2026:

The UEM server, for each unique policy managed, must validate the policy is appropriate for an agent using [selection: a private key associated with an X509 certificate representing the agent, a token issued by the agent] associated with a policy signing key uniquely associated with the policy.

DISA Rule

SV-264369r1213325_rule

Vulnerability Number

V-264369

Group Title

SRG-APP-000427

Rule Version

SRG-APP-000427-UEM-000502

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the IUEM server, for each unique policy managed, to validate the policy is appropriate for an agent using [selection: a private key associated with an X509 certificate representing the agent, a token issued by the agent and associated with a policy signing key uniquely associated with the policy].

Check Contents

Verify the UEM server, for each unique policy managed, validates the policy is appropriate for an agent using [selection: a private key associated with an X509 certificate representing the agent, a token issued by the agent and associated with a policy signing key uniquely associated with the policy].

If the UEM server does not validate the policy is appropriate for an agent using [selection: a private key associated with an X509 certificate representing the agent, a token issued by the agent and associated with a policy signing key uniquely associated with the policy, this is a finding.

Vulnerability Number

V-264369

Documentable

False

Rule Version

SRG-APP-000427-UEM-000502

Severity Override Guidance

Verify the UEM server, for each unique policy managed, validates the policy is appropriate for an agent using [selection: a private key associated with an X509 certificate representing the agent, a token issued by the agent and associated with a policy signing key uniquely associated with the policy].

If the UEM server does not validate the policy is appropriate for an agent using [selection: a private key associated with an X509 certificate representing the agent, a token issued by the agent and associated with a policy signing key uniquely associated with the policy, this is a finding.

Check Content Reference

M

Target Key

5269