STIGQter STIGQter: STIG Summary: Omnissa WS1 UEM Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 May 2026:

The Omnissa WS1 UEM server must be configured to have at least one user in defined administrator roles.

DISA Rule

SV-284358r1224101_rule

Vulnerability Number

V-284358

Group Title

SRG-APP-000329-UEM-000202

Rule Version

OMW1-00-013100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Accounts >> Administrators >> Admin Roles.

From the Roles page, locate the following predefined roles:

- AirWatch Administrator.
- Device Manager.
- Read Only.

Ensure that at least one user exists in each group or the org-defined replacement roles.

Ensure that the "AirWatch Administrator" and "Device Manager" roles are restricted to the smallest possible set of administrators following least privilege principles.

Check Contents

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Accounts >> Administrators >> Admin Roles.

From the Roles page, locate the following predefined roles:

- AirWatch Administrator.
- Device Manager.
- Read Only.

If any role above does not have at least one member, this is a finding.

If the "AirWatch Administrator" and "Device Manager" roles are not restricted to the smallest possible set of administrators following least privilege principles, this is a finding.

If any of these predefined roles were removed in favor of org-defined roles, ensure that these new roles duplicate the functionality of the default roles, as described in the discussion. If they do not, this is a finding.

Vulnerability Number

V-284358

Documentable

False

Rule Version

OMW1-00-013100

Severity Override Guidance

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Accounts >> Administrators >> Admin Roles.

From the Roles page, locate the following predefined roles:

- AirWatch Administrator.
- Device Manager.
- Read Only.

If any role above does not have at least one member, this is a finding.

If the "AirWatch Administrator" and "Device Manager" roles are not restricted to the smallest possible set of administrators following least privilege principles, this is a finding.

If any of these predefined roles were removed in favor of org-defined roles, ensure that these new roles duplicate the functionality of the default roles, as described in the discussion. If they do not, this is a finding.

Check Content Reference

M

Target Key

5751