STIGQter STIGQter: STIG Summary: Omnissa WS1 UEM Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 May 2026:

The Omnissa WS1 UEM server must be configured to use a directory service for centralized account management.

DISA Rule

SV-284254r1223995_rule

Vulnerability Number

V-284254

Group Title

SRG-APP-000023-UEM-000012

Rule Version

OMW1-00-000600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Set up directory service integration.
a. Authenticate to the Workspace ONE UEM console as an administrator.
b. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Directory Services. Select "Skip wizard and configure manually".
c. Under the "Server" tab, complete the directory service connection information. This will be site-specific. Consult Omnissa documentation for "Directory Services Setup" for details.
d. Click "Save".

2. Require that device enrollment only uses directory service authentication.
a. Navigate to Groups & Settings >> All Settings >> Devices and Users >> General >> Enrollment.
b. Under the "Authentication" tab, find the "Authentication Modes" setting.
c. Ensure that "Directory" is the one and only checked box.
d. Click "Save".

3. Remove all admin accounts that are not the "break-glass" account.
a. Navigate to Accounts >> Administrators >> List View.
b. For each user with an "Admin Type" of "Basic" that is NOT the "break-glass" account, select the three vertical dots next to that user and then select "Delete".
c. Click "Delete" when prompted to confirm.

4. Remove all users that are not centrally managed by a directory service.
a. Navigate to Accounts >> Users >> List View.
b. Click "Layout" and select "Custom".
c. For each user with a "Security Type" of "Basic", select the checkbox next to the user.
d. Click "More Actions", then click "Delete".
e. To confirm, click "Save" when prompted.

Check Contents

1. Verify directory service integration.
a. Authenticate to the Workspace ONE UEM console as an administrator.
b. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Directory Services. Select "Skip wizard and configure manually".
c. Under the "Server" tab, verify directory service connection information.

If no valid directory service is configured, this is a finding.

In the bottom right, click "Test Connection".

If the test is not successful, this is a finding.

2. Validate that device enrollment uses directory service authentication only.
a. Navigate to Groups & Settings >> All Settings >> Devices and Users >> General >> Enrollment.
b. Under the "Authentication" tab, find the "Authentication Modes" setting.

If "Directory" is not the one and only checked box, this is a finding.

3. Validate there is only one "break-glass" local admin configured.
a. Navigate to Accounts >> Administrators >> List View.
b. Review account types under the "Admin Type" column. If any users have an "Admin Type" of "Basic", outside of a single "break-glass" admin, this is a finding.

4. Validate that all users are centrally managed by a directory service.
a. Navigate to Accounts >> Users >> List View.
b. Click "Layout" and select "Custom".
c. Under the "Security Type" column, if any "Basic" accounts are listed, this is a finding.

Vulnerability Number

V-284254

Documentable

False

Rule Version

OMW1-00-000600

Severity Override Guidance

1. Verify directory service integration.
a. Authenticate to the Workspace ONE UEM console as an administrator.
b. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Directory Services. Select "Skip wizard and configure manually".
c. Under the "Server" tab, verify directory service connection information.

If no valid directory service is configured, this is a finding.

In the bottom right, click "Test Connection".

If the test is not successful, this is a finding.

2. Validate that device enrollment uses directory service authentication only.
a. Navigate to Groups & Settings >> All Settings >> Devices and Users >> General >> Enrollment.
b. Under the "Authentication" tab, find the "Authentication Modes" setting.

If "Directory" is not the one and only checked box, this is a finding.

3. Validate there is only one "break-glass" local admin configured.
a. Navigate to Accounts >> Administrators >> List View.
b. Review account types under the "Admin Type" column. If any users have an "Admin Type" of "Basic", outside of a single "break-glass" admin, this is a finding.

4. Validate that all users are centrally managed by a directory service.
a. Navigate to Accounts >> Users >> List View.
b. Click "Layout" and select "Custom".
c. Under the "Security Type" column, if any "Basic" accounts are listed, this is a finding.

Check Content Reference

M

Target Key

5751