STIGQter STIGQter: STIG Summary: Omnissa WS1 UEM API Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 May 2026:

The Omnissa WS1 UEM API must be configured to use approved authorizations for access control.

DISA Rule

SV-284174r1223915_rule

Vulnerability Number

V-284174

Group Title

SRG-APP-000033-API-000070

Rule Version

OMW1-API-000200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Implement WS1 UEM REST API access control has been configured to require "Directory" authentication using the following procedures:

1. Log in to the WS1 UEM console.
2. Navigate to Groups & Settings >> All Settings >> System >> Advanced >> API >> REST API >> Authentication tab.
3. If the configuration is already set as listed in step 4 below, select "Inherent". If the configuration is not already set as listed in step 4 below, select "Override".
4. Select the following settings: Basic - "Disabled", Certificates - "Disabled", and Directory - "Enabled".
5. For Child Permission, select "Inherit only".

Check Contents

Verify WS1 UEM REST API access control has been configured to require "Directory" authentication.

1. Log in to the WS1 UEM console.
2. Navigate to Groups & Settings >> All Settings >> System >> Advanced >> API >> REST API >> Authentication tab.
3. Verify the authentication configuration is set correctly: Basic - "Disabled", Certificates - "Disabled", and Directory - "Enabled".
4. Verify the Child Permission is set to "Inherit only".

If the WS1 UEM REST API authentication is not set correctly, this is a finding.

Vulnerability Number

V-284174

Documentable

False

Rule Version

OMW1-API-000200

Severity Override Guidance

Verify WS1 UEM REST API access control has been configured to require "Directory" authentication.

1. Log in to the WS1 UEM console.
2. Navigate to Groups & Settings >> All Settings >> System >> Advanced >> API >> REST API >> Authentication tab.
3. Verify the authentication configuration is set correctly: Basic - "Disabled", Certificates - "Disabled", and Directory - "Enabled".
4. Verify the Child Permission is set to "Inherit only".

If the WS1 UEM REST API authentication is not set correctly, this is a finding.

Check Content Reference

M

Target Key

5749