STIGQter STIGQter: STIG Summary: Omnissa WS1 UEM Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 May 2026:

The Omnissa WS1 UEM server must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

DISA Rule

SV-284260r1224001_rule

Vulnerability Number

V-284260

Group Title

SRG-APP-000065-UEM-000036

Rule Version

OMW1-00-001300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords.

Next to "Maximum invalid login attempts", enter "3". Click "Save".

Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.

Check Contents

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords.

If "Maximum invalid login attempts" is not set to "3", this is a finding.

Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.

Vulnerability Number

V-284260

Documentable

False

Rule Version

OMW1-00-001300

Severity Override Guidance

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords.

If "Maximum invalid login attempts" is not set to "3", this is a finding.

Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.

Check Content Reference

M

Target Key

5751