STIGQter STIGQter: STIG Summary: AvePoint Fly Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

Fly Server must have no local accounts for the user interface.

DISA Rule

SV-283938r1223357_rule

Vulnerability Number

V-283938

Group Title

SRG-APP-000150

Rule Version

FLYS-00-000110

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Once Active Directory is configured in FLYS-00-000055, remove all local users:
- On the Management >> Account Manager tab, remove all local users.

Check Contents

Once Active Directory is configured in FLYS-00-000055, all local users must be removed.

Check the Fly Server User settings:
- On the Management >> Account Manager tab, view the list of users.
- User accounts tied to an Active Directory domain will be defined as [domainname]\[username].

If any of the users listed are not tied to Active Directory, this is a finding.

Vulnerability Number

V-283938

Documentable

False

Rule Version

FLYS-00-000110

Severity Override Guidance

Once Active Directory is configured in FLYS-00-000055, all local users must be removed.

Check the Fly Server User settings:
- On the Management >> Account Manager tab, view the list of users.
- User accounts tied to an Active Directory domain will be defined as [domainname]\[username].

If any of the users listed are not tied to Active Directory, this is a finding.

Check Content Reference

M

Target Key

5747