STIGQter STIGQter: STIG Summary: Omnissa WS1 UEM Agent Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 May 2026:

The Omnissa WS1 UEM Agent must be configured to enable the following function: Read audit logs of the managed endpoint device: Android.

DISA Rule

SV-284237r1223978_rule

Vulnerability Number

V-284237

Group Title

SRG-APP-000089-UEM-100012

Rule Version

OMW1-00-100350

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the MDM Agent to enable the following function:

Read audit logs of the MD.

On the MDM console, do the following:

1. Authenticate to the Workspace ONE UEM console as the administrator.
2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy. Enable "Request Device Log" in the privacy settings.
3. Select "Save".

Check Contents

Review the MDM Agent documentation and configuration settings to determine if the following function is enabled:

Read audit logs of the MD.

This validation procedure is performed on the MDM Administration Console.

On the MDM console, do the following:

1. Authenticate to the Workspace ONE UEM console as the administrator.
2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy. Enable "Request Device Log" in the privacy settings.

If "Request Device Log" is present, then no device log is being requested from the MD, and this is a finding.

Vulnerability Number

V-284237

Documentable

False

Rule Version

OMW1-00-100350

Severity Override Guidance

Review the MDM Agent documentation and configuration settings to determine if the following function is enabled:

Read audit logs of the MD.

This validation procedure is performed on the MDM Administration Console.

On the MDM console, do the following:

1. Authenticate to the Workspace ONE UEM console as the administrator.
2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy. Enable "Request Device Log" in the privacy settings.

If "Request Device Log" is present, then no device log is being requested from the MD, and this is a finding.

Check Content Reference

M

Target Key

5750