STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must use multifactor authentication for local access to privileged accounts.

DISA Rule

SV-279435r1191091_rule

Vulnerability Number

V-279435

Group Title

SRG-APP-000151-AS-000103

Rule Version

NXAC-AS-000029

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the Nutanix VM application server to use an enterprise user management system to authenticate individual users.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
4. Add an Active Directory or OpenLDAP server to the directory list.

Alternatively, individual local users can be created within Prism.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Local User Management.
4. Select "+ New Users".

Check Contents

Confirm the Nutanix VM application server Envoy Reverse Proxy server only has one local account, and that it is the account of last resort. The Envoy Reverse Proxy server relies on AD for user management.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.

If an Active Directory or OpenLDAP servers are not configured, this is a finding.

Vulnerability Number

V-279435

Documentable

False

Rule Version

NXAC-AS-000029

Severity Override Guidance

Confirm the Nutanix VM application server Envoy Reverse Proxy server only has one local account, and that it is the account of last resort. The Envoy Reverse Proxy server relies on AD for user management.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.

If an Active Directory or OpenLDAP servers are not configured, this is a finding.

Check Content Reference

M

Target Key

5729