STIGQter STIGQter: STIG Summary: AvePoint Fly Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

Fly Server must automatically disable accounts after a 35-day period of account inactivity.

DISA Rule

SV-283925r1206871_rule

Vulnerability Number

V-283925

Group Title

SRG-APP-000025

Rule Version

FLYS-00-000015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Fly Server security settings:
- Log on to Fly Server Manager with the administrator account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Navigate to "User Settings", then click "Deactivate a user after 35 days of inactivity" option.
- Set 35 days or other values as required.
- Save the setting.

Check Contents

Check the Fly Server security settings:
- Log on to Fly Server Manager with the admin account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Navigate to "User Settings".
- Verify the "Deactivate a user after 35 days of inactivity" option is checked.

If this option is not checked, this is a finding.

Vulnerability Number

V-283925

Documentable

False

Rule Version

FLYS-00-000015

Severity Override Guidance

Check the Fly Server security settings:
- Log on to Fly Server Manager with the admin account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Navigate to "User Settings".
- Verify the "Deactivate a user after 35 days of inactivity" option is checked.

If this option is not checked, this is a finding.

Check Content Reference

M

Target Key

5747