STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must accept Federal Identity, Credential, and Access Management (FICAM)-approved third-party credentials.

DISA Rule

SV-279443r1192354_rule

Vulnerability Number

V-279443

Group Title

SRG-APP-000404-AS-000249

Rule Version

NXAC-AS-000042

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nutanix VM application server Prism Element to use FICAM authentication.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
4. Select "Configure SAML Authentication Account" check box, and then do the following in the indicated fields:
a. Select the authentication directory that contains the CAC users to authenticate. This list includes the directories that are configured on the directory list tab.
b. Service Username: Enter the username in the username@domain.com for the web console to use to log in to the Active Directory.
c. Service Password: Enter the password for the service username.
d. Click "Enable CAC".

Check Contents

If configured, Confirm the Nutanix VM application server Prism Element is configured to accept FICAM-approved third party credentials.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
4. Verify a SAML-based identity provider is configured.

If a SAML-based identity provider is not configured, this is a finding.

Vulnerability Number

V-279443

Documentable

False

Rule Version

NXAC-AS-000042

Severity Override Guidance

If configured, Confirm the Nutanix VM application server Prism Element is configured to accept FICAM-approved third party credentials.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
4. Verify a SAML-based identity provider is configured.

If a SAML-based identity provider is not configured, this is a finding.

Check Content Reference

M

Target Key

5729