STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must use multifactor authentication for access to privileged and nonprivileged accounts by enabling common access card (CAC) authentication.

DISA Rule

SV-279434r1192622_rule

Vulnerability Number

V-279434

Group Title

SRG-APP-000149-AS-000102

Rule Version

NXAC-AS-000028

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the Nutanix AOS to use a centralized AAA server that uses DOD PKI to authenticate individual users.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to the Authentication settings.
4. Select the "Configure Service Account" check box and then complete the following in the indicated fields:
a. Select the authentication directory that contains the CAC users to be authenticated. This list includes the directories configured on the Directory List tab.
b. Service Username: Enter the username in the username@domain.com format the web console will use to log in to the Active Directory.
c. Service Password: Enter the password for the service username.
d. Click "Enable CAC".

Check Contents

Verify the Nutanix AOS uses a centralized AAA server that uses DOD PKI to authenticate individual users.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to the Authentication settings.

If CAC authentication is not enabled, this is a finding.

Vulnerability Number

V-279434

Documentable

False

Rule Version

NXAC-AS-000028

Severity Override Guidance

Verify the Nutanix AOS uses a centralized AAA server that uses DOD PKI to authenticate individual users.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to the Authentication settings.

If CAC authentication is not enabled, this is a finding.

Check Content Reference

M

Target Key

5729