SV-284254r1223995_rule
V-284254
SRG-APP-000023-UEM-000012
OMW1-00-000600
CAT II
10
1. Set up directory service integration.
a. Authenticate to the Workspace ONE UEM console as an administrator.
b. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Directory Services. Select "Skip wizard and configure manually".
c. Under the "Server" tab, complete the directory service connection information. This will be site-specific. Consult Omnissa documentation for "Directory Services Setup" for details.
d. Click "Save".
2. Require that device enrollment only uses directory service authentication.
a. Navigate to Groups & Settings >> All Settings >> Devices and Users >> General >> Enrollment.
b. Under the "Authentication" tab, find the "Authentication Modes" setting.
c. Ensure that "Directory" is the one and only checked box.
d. Click "Save".
3. Remove all admin accounts that are not the "break-glass" account.
a. Navigate to Accounts >> Administrators >> List View.
b. For each user with an "Admin Type" of "Basic" that is NOT the "break-glass" account, select the three vertical dots next to that user and then select "Delete".
c. Click "Delete" when prompted to confirm.
4. Remove all users that are not centrally managed by a directory service.
a. Navigate to Accounts >> Users >> List View.
b. Click "Layout" and select "Custom".
c. For each user with a "Security Type" of "Basic", select the checkbox next to the user.
d. Click "More Actions", then click "Delete".
e. To confirm, click "Save" when prompted.
1. Verify directory service integration.
a. Authenticate to the Workspace ONE UEM console as an administrator.
b. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Directory Services. Select "Skip wizard and configure manually".
c. Under the "Server" tab, verify directory service connection information.
If no valid directory service is configured, this is a finding.
In the bottom right, click "Test Connection".
If the test is not successful, this is a finding.
2. Validate that device enrollment uses directory service authentication only.
a. Navigate to Groups & Settings >> All Settings >> Devices and Users >> General >> Enrollment.
b. Under the "Authentication" tab, find the "Authentication Modes" setting.
If "Directory" is not the one and only checked box, this is a finding.
3. Validate there is only one "break-glass" local admin configured.
a. Navigate to Accounts >> Administrators >> List View.
b. Review account types under the "Admin Type" column. If any users have an "Admin Type" of "Basic", outside of a single "break-glass" admin, this is a finding.
4. Validate that all users are centrally managed by a directory service.
a. Navigate to Accounts >> Users >> List View.
b. Click "Layout" and select "Custom".
c. Under the "Security Type" column, if any "Basic" accounts are listed, this is a finding.
V-284254
False
OMW1-00-000600
1. Verify directory service integration.
a. Authenticate to the Workspace ONE UEM console as an administrator.
b. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Directory Services. Select "Skip wizard and configure manually".
c. Under the "Server" tab, verify directory service connection information.
If no valid directory service is configured, this is a finding.
In the bottom right, click "Test Connection".
If the test is not successful, this is a finding.
2. Validate that device enrollment uses directory service authentication only.
a. Navigate to Groups & Settings >> All Settings >> Devices and Users >> General >> Enrollment.
b. Under the "Authentication" tab, find the "Authentication Modes" setting.
If "Directory" is not the one and only checked box, this is a finding.
3. Validate there is only one "break-glass" local admin configured.
a. Navigate to Accounts >> Administrators >> List View.
b. Review account types under the "Admin Type" column. If any users have an "Admin Type" of "Basic", outside of a single "break-glass" admin, this is a finding.
4. Validate that all users are centrally managed by a directory service.
a. Navigate to Accounts >> Users >> List View.
b. Click "Layout" and select "Custom".
c. Under the "Security Type" column, if any "Basic" accounts are listed, this is a finding.
M
5751