SV-284358r1224101_rule
V-284358
SRG-APP-000329-UEM-000202
OMW1-00-013100
CAT II
10
Authenticate to the Workspace ONE UEM console as an administrator.
Navigate to Accounts >> Administrators >> Admin Roles.
From the Roles page, locate the following predefined roles:
- AirWatch Administrator.
- Device Manager.
- Read Only.
Ensure that at least one user exists in each group or the org-defined replacement roles.
Ensure that the "AirWatch Administrator" and "Device Manager" roles are restricted to the smallest possible set of administrators following least privilege principles.
Authenticate to the Workspace ONE UEM console as an administrator.
Navigate to Accounts >> Administrators >> Admin Roles.
From the Roles page, locate the following predefined roles:
- AirWatch Administrator.
- Device Manager.
- Read Only.
If any role above does not have at least one member, this is a finding.
If the "AirWatch Administrator" and "Device Manager" roles are not restricted to the smallest possible set of administrators following least privilege principles, this is a finding.
If any of these predefined roles were removed in favor of org-defined roles, ensure that these new roles duplicate the functionality of the default roles, as described in the discussion. If they do not, this is a finding.
V-284358
False
OMW1-00-013100
Authenticate to the Workspace ONE UEM console as an administrator.
Navigate to Accounts >> Administrators >> Admin Roles.
From the Roles page, locate the following predefined roles:
- AirWatch Administrator.
- Device Manager.
- Read Only.
If any role above does not have at least one member, this is a finding.
If the "AirWatch Administrator" and "Device Manager" roles are not restricted to the smallest possible set of administrators following least privilege principles, this is a finding.
If any of these predefined roles were removed in favor of org-defined roles, ensure that these new roles duplicate the functionality of the default roles, as described in the discussion. If they do not, this is a finding.
M
5751