STIGQter STIGQter: STIG Summary: Omnissa WS1 UEM Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 May 2026:

The Omnissa WS1 UEM server must be configured to require a One-Time Password (OTP) or Short Message Service (SMS) two-factor authentication for local accounts.

DISA Rule

SV-284284r1224027_rule

Vulnerability Number

V-284284

Group Title

SRG-APP-000149-UEM-000083

Rule Version

OMW1-00-004020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Authenticate to the Workspace ONE UEM console as an administrator.

1. Navigate to Accounts >> Administrators >> List View.
2. For each account with an "Admin Type" of "Basic", click the three vertical dots next to the account name and select "Edit".
3. Click "Next" three times to reach the "Settings" page.
4. Enable "Two Factor Authentication" and configure either email or SMS notification.
5. Click "Save".

Note: The OTP code will be sent to the email or mobile phone configured on the previous pages. Ensure they are configured correctly.

Note: The only authorized local account is the "break-glass" account.

Check Contents

Authenticate to the Workspace ONE UEM console as an administrator.

1. Navigate to Accounts >> Administrators >> List View.
2. For each account with an "Admin Type" of "Basic", click the three vertical dots next to the account name and select "Edit".
3. Click "Next" three times to reach the "Settings" page.

If "Two Factor Authentication" is not enabled, this is a finding.

If the account has the "Read Only" role and is used for automation such as compliance scanning, this is not applicable to that account.

Vulnerability Number

V-284284

Documentable

False

Rule Version

OMW1-00-004020

Severity Override Guidance

Authenticate to the Workspace ONE UEM console as an administrator.

1. Navigate to Accounts >> Administrators >> List View.
2. For each account with an "Admin Type" of "Basic", click the three vertical dots next to the account name and select "Edit".
3. Click "Next" three times to reach the "Settings" page.

If "Two Factor Authentication" is not enabled, this is a finding.

If the account has the "Read Only" role and is used for automation such as compliance scanning, this is not applicable to that account.

Check Content Reference

M

Target Key

5751