STIGQter STIGQter: STIG Summary: Active Directory Domain Security Technical Implementation Guide (STIG) Version: 2 Release: 13 Benchmark Date: 26 Apr 2019:

Selective Authentication must be enabled on outgoing forest trusts.

DISA Rule

SV-9037r3_rule

Vulnerability Number

V-8540

Group Title

Trust - Selective Authentication

Rule Version

AD.0200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable Selective Authentication on outgoing forest trust.
Open "Active Directory Domains and Trusts". (Available from various menus or run "domain.msc".)
Right click the domain name in the left pane and select "Properties".
Select the "Trusts" tab.
For each outgoing forest trust, right-click the trust item and select "Properties".
Select the "Authentication" tab.
Select the "Selective Authentication" option.
(It may be necessary to configure the "Allowed to Authenticate" permission on resources in the trusting domain.)

Check Contents

Open "Active Directory Domains and Trusts". (Available from various menus or run "domain.msc".)
Right click the domain name in the left pane and select "Properties".
Select the "Trusts" tab.
For each outgoing forest trust, right-click the trust item and select "Properties".
Select the "Authentication" tab.

If the "Selective Authentication" option is not selected on every outgoing forest trust, this is a finding.

Vulnerability Number

V-8540

Documentable

False

Rule Version

AD.0200

Severity Override Guidance

Open "Active Directory Domains and Trusts". (Available from various menus or run "domain.msc".)
Right click the domain name in the left pane and select "Properties".
Select the "Trusts" tab.
For each outgoing forest trust, right-click the trust item and select "Properties".
Select the "Authentication" tab.

If the "Selective Authentication" option is not selected on every outgoing forest trust, this is a finding.

Check Content Reference

M

Potential Impact

Implementation requires configuration of the Allowed to Authenticate permission on resources in the trusting domain for which access is desired. Failure to configure this permission could result in operational problems including denied resource access to authorized users.

Responsibility

Information Assurance Officer

Target Key

870

Comments