SV-284174r1223915_rule
V-284174
SRG-APP-000033-API-000070
OMW1-API-000200
CAT II
10
Implement WS1 UEM REST API access control has been configured to require "Directory" authentication using the following procedures:
1. Log in to the WS1 UEM console.
2. Navigate to Groups & Settings >> All Settings >> System >> Advanced >> API >> REST API >> Authentication tab.
3. If the configuration is already set as listed in step 4 below, select "Inherent". If the configuration is not already set as listed in step 4 below, select "Override".
4. Select the following settings: Basic - "Disabled", Certificates - "Disabled", and Directory - "Enabled".
5. For Child Permission, select "Inherit only".
Verify WS1 UEM REST API access control has been configured to require "Directory" authentication.
1. Log in to the WS1 UEM console.
2. Navigate to Groups & Settings >> All Settings >> System >> Advanced >> API >> REST API >> Authentication tab.
3. Verify the authentication configuration is set correctly: Basic - "Disabled", Certificates - "Disabled", and Directory - "Enabled".
4. Verify the Child Permission is set to "Inherit only".
If the WS1 UEM REST API authentication is not set correctly, this is a finding.
V-284174
False
OMW1-API-000200
Verify WS1 UEM REST API access control has been configured to require "Directory" authentication.
1. Log in to the WS1 UEM console.
2. Navigate to Groups & Settings >> All Settings >> System >> Advanced >> API >> REST API >> Authentication tab.
3. Verify the authentication configuration is set correctly: Basic - "Disabled", Certificates - "Disabled", and Directory - "Enabled".
4. Verify the Child Permission is set to "Inherit only".
If the WS1 UEM REST API authentication is not set correctly, this is a finding.
M
5749