STIGQter STIGQter: STIG Summary: Omnissa WS1 UEM Agent Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 May 2026:

The Omnissa WS1 UEM Agent must be configured to perform one of the following actions upon an attempt to unenroll the mobile device from management: - Prevent the unenrollment from occurring. - Wipe the device to factory default settings. - Wipe the work profile with all associated applications and data.

DISA Rule

SV-284246r1223987_rule

Vulnerability Number

V-284246

Group Title

SRG-APP-000516-UEM-100011

Rule Version

OMW1-00-101300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings.

Find "Block User Unenrollment" and choose "Enabled". Click "Save".

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment.

Edit the DEP profile and navigate to "MDM features". Choose "Enabled" for "Lock MDM Profile". Click "Save".

Check Contents

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings.

If "Block User Unenrollment" is not "Enabled", this is a finding.

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment.

Edit the DEP profile and navigate to "MDM features". If "Lock MDM Profile" is not "Enabled", this is a finding.

Vulnerability Number

V-284246

Documentable

False

Rule Version

OMW1-00-101300

Severity Override Guidance

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings.

If "Block User Unenrollment" is not "Enabled", this is a finding.

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment.

Edit the DEP profile and navigate to "MDM features". If "Lock MDM Profile" is not "Enabled", this is a finding.

Check Content Reference

M

Target Key

5750