STIGQter STIGQter: STIG Summary:

Unified Endpoint Management Server Security Requirements Guide

Version: 2

Release: 5 Benchmark Date: 29 Jun 2026

CheckedNameTitle
SV-234275r1212890_ruleThe UEM server must limit the number of concurrent sessions per privileged user account to three or less concurrent sessions.
SV-234276r1212891_ruleThe UEM server must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
SV-234277r1212892_ruleThe UEM server must initiate a session lock after a 15-minute period of inactivity.
SV-234278r1212893_ruleThe MDM server must provide the capability for users to directly initiate a session lock.
SV-234279r1212894_ruleThe MDM server must retain the session lock until the user reestablishes access using established identification and authentication procedures.
SV-234283r1212898_ruleThe UEM server must use TLS 1.2, or higher, to protect the confidentiality of sensitive data during electronic dissemination using remote access.
SV-234286r1212902_ruleThe UEM server must provide automated mechanisms for supporting account management functions.
SV-234287r1212904_ruleThe UEM server must automatically remove or disable temporary user accounts after 72 hours if supported by the UEM server.
SV-234288r1212906_ruleThe UEM server must automatically disable accounts after a 35-day period of account inactivity.
SV-234289r1212908_ruleThe UEM server must automatically audit account creation.
SV-234290r1212910_ruleThe UEM server must automatically audit account modification.
SV-234291r1212912_ruleThe UEM server must automatically audit account disabling actions.
SV-234292r1212914_ruleThe UEM server must automatically audit account removal actions.
SV-234310r1212933_ruleThe UEM server must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-234311r1212936_ruleThe UEM server must display the Standard Mandatory DoW Notice and Consent Banner before granting access to the application.
SV-234312r1212937_ruleThe UEM server must retain the access banner until the user acknowledges acceptance of the access conditions.
SV-234318r1212943_ruleThe UEM server must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by nonrepudiation.
SV-234323r1212950_ruleThe UEM server must provide audit record generation capability for DoW-defined auditable events within all application components.
SV-234324r1212951_ruleThe UEM server must be configured to provide audit records in a manner suitable for the authorized administrators to interpret the information.
SV-234325r1212952_ruleThe UEM server must be configured to allow only specific administrator roles to select which auditable events are to be audited.
SV-234326r1212953_ruleThe UEM server must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-234327r1212954_ruleThe UEM server must initiate session auditing upon startup.
SV-234328r1212955_ruleThe UEM server must be configured to produce audit records containing information to establish what type of events occurred.
SV-234329r1212956_ruleThe UEM server must be configured to produce audit records containing information to establish when (date and time) the events occurred.
SV-234330r1212957_ruleThe UEM server must be configured to produce audit records containing information to establish where the events occurred.
SV-234331r1212958_ruleThe UEM server must be configured to produce audit records containing information to establish the source of the events.
SV-234332r1212959_ruleThe UEM server must be configured to produce audit records that contain information to establish the outcome of the events.
SV-234333r1212960_ruleThe UEM server must be configured to generate audit records containing information that establishes the identity of any individual or process associated with the event.
SV-234334r1212961_ruleThe UEM server must be configured to generate audit records containing the full-text recording of privileged commands or the individual identities of group account users.
SV-234335r1212962_ruleThe UEM SRG must alert the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.
SV-234340r1212967_ruleThe UEM server must use host operating system clocks to generate time stamps for audit records.
SV-234341r1212968_ruleThe UEM server must protect audit information from any type of unauthorized read access.
SV-234342r1212969_ruleThe UEM server must protect audit information from unauthorized modification.
SV-234343r1212970_ruleThe UEM server must protect audit information from unauthorized deletion.
SV-234347r1212974_ruleThe UEM server must back up audit records at least every seven days onto a log management server.
SV-234349r1212976_ruleThe UEM server must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
SV-234351r1212978_ruleThe UEM server must limit privileges to change the software resident within software libraries.
SV-234352r1212979_ruleThe UEM server must be configured to disable nonessential capabilities.
SV-234353r1212982_ruleThe firewall protecting the UEM server platform must be configured so only DoW-approved ports, protocols, and services are enabled. (Refer to the DoW Ports, Protocols, Services Management [PPSM] Category Assurance Levels [CAL] list for DoW-approved ports, protocols, and services).
SV-234355r1212985_ruleThe UEM server must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-234356r1212988_ruleThe UEM server must be configured to use a DoW Central Directory Service to provide multifactor authentication for network access to privileged and nonprivileged accounts.
SV-234358r1212990_ruleAll UEM server local accounts created during application installation and configuration must be removed. Note: In this context local accounts refers to user and or administrator accounts on the server that use user name and password for user access and authentication.
SV-234360r1212993_ruleThe UEM server must ensure users are authenticated with an individual authenticator prior to using a group authenticator.
SV-234361r1212996_ruleThe UEM server must be configured to use DoW PKI for multifactor authentication. This requirement is included in SRG-APP-000149.
SV-234363r1212999_ruleThe UEM server must use FIPS-validated SHA-2 or higher hash function to provide replay-resistant authentication mechanisms for network access to privileged accounts.
SV-234364r1213001_ruleThe UEM server must implement replay-resistant authentication mechanisms for network access to nonprivileged accounts.
SV-234367r1213003_ruleThe UEM server must enforce a minimum 15-character password length.
SV-234368r1213004_ruleThe UEM server must prohibit password reuse for a minimum of five generations.
SV-234369r1213005_ruleThe UEM server must enforce password complexity by requiring that at least one uppercase character be used.
SV-234370r1213006_ruleThe UEM server must enforce password complexity by requiring that at least one lowercase character be used.
SV-234371r1213007_ruleThe UEM server must enforce password complexity by requiring that at least one numeric character be used.
SV-234372r1213008_ruleThe UEM server must enforce password complexity by requiring that at least one special character be used.
SV-234373r1213009_ruleUEM server must require the change of at least 50 percent of the previous password's characters.
SV-234374r1213010_ruleFor UEM server using password authentication, the application must store only cryptographic representations of passwords.
SV-234375r1213011_ruleFor UEM server using password authentication, the network element must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
SV-234377r1213012_ruleThe UEM server must enforce a 60-day maximum password lifetime restriction.
SV-234378r1213014_ruleWhen using PKI-based authentication for user access, the UEM server must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-234379r1213015_ruleWhen the UEM server cannot establish a connection to determine the validity of a certificate, the server must be configured not to have the option to accept the certificate.
SV-234380r1213017_ruleThe UEM server, when using PKI-based authentication, must enforce authorized access to the corresponding private key.
SV-234381r1213019_ruleThe UEM server must map the authenticated identity to the individual user or group account for PKI-based authentication.
SV-234382r1213020_ruleThe UEM server must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.
SV-234383r1213021_ruleThe UEM server must use FIPS-validated SHA-2 or higher hash function to protect the integrity of keyed-hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, and hash-only applications.
SV-234390r1213027_ruleThe UEM server must be configured to provide a trusted communication channel between itself and authorized IT entities using [selection: -IPsec, -SSH, -mutually authenticated TLS, -mutually authenticated DTLS, -HTTPS].
SV-234391r1213028_ruleThe UEM server must be configured to invoke either host-OS functionality or server functionality to provide a trusted communication channel between itself and remote administrators that provides assured identification of its endpoints and protection of the communicated data from modification and disclosure using [selection: -IPsec, -SSH, -TLS, -HTTPS].
SV-234392r1213029_ruleThe UEM server must be configured to invoke either host-OS functionality or server functionality to provide a trusted communication channel between itself and managed devices that provides assured identification of its endpoints and protection of the communicated data from modification and disclosure using [selection: -TLS, -HTTPS].
SV-234405r1213042_ruleThe UEM server must protect the authenticity of communications sessions.
SV-234406r1213043_ruleThe UEM server must invalidate session identifiers upon user logout or other session termination.
SV-234407r1213044_ruleThe UEM server must recognize only system-generated session identifiers.
SV-234408r1213045_ruleThe UEM server must generate unique session identifiers using a FIPS-validated Random Number Generator (RNG) based on the Deterministic Random Bit Generators (DRBG) algorithm.
SV-234409r1213046_ruleThe UEM server must fail to a secure state if system initialization fails, shutdown fails, or aborts fail.
SV-234410r1213047_ruleIn the event of a system failure, the UEM server must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.
SV-234421r1213059_ruleThe UEM server must check the validity of all data inputs.
SV-234424r1213062_ruleThe UEM server must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-234425r1213063_ruleThe UEM server must reveal error messages only to the information system security manager (ISSM) and information system security officer (ISSO).
SV-234430r1213067_ruleThe application must notify the information system security manager (ISSM) and information system security officer (ISSO) of failed security verification tests.
SV-234438r1213075_ruleThe UEM server must notify system administrators (SAs) and the information system security officer (ISSO) when accounts are created.
SV-234439r1213077_ruleThe UEM server must notify system administrators (SAs) and the information system security officer (ISSO) when accounts are modified.
SV-234440r1213079_ruleThe UEM server must notify system administrators (SAs) and the information system security officer (ISSO) for account disabling actions.
SV-234441r1213081_ruleThe UEM server must notify system administrators (SAs) and the information system security officer (ISSO) for account removal actions.
SV-234442r1213082_ruleThe UEM server must automatically terminate a user session after an organization-defined period of user inactivity.
SV-234443r1213083_ruleThe UEM server must provide logout capability for user-initiated communication sessions.
SV-234444r1213084_ruleThe UEM server must display an explicit logout message to users indicating the reliable termination of authenticated communications sessions.
SV-234465r1213106_ruleThe UEM server must automatically audit account-enabling actions.
SV-234466r1213108_ruleThe UEM server must notify system administrator (SA) and information system security officer (ISSO) of account enabling actions.
SV-234475r1213117_ruleThe UEM server must be configured to have at least one user in defined administrator roles.
SV-234489r1213130_ruleThe UEM server must audit the execution of privileged functions.
SV-234491r1213133_ruleThe UEM server must automatically lock the account until the locked account is released by an administrator when three unsuccessful login attempts in 15 minutes are exceeded.
SV-234500r1213141_ruleThe UEM server must be configured to transfer UEM server logs to another server for storage, analysis, and reporting. Note: UEM server logs include logs of UEM events and logs transferred to the UEM server by UEM agents of managed devices.
SV-234516r1213157_ruleThe UEM server must be configured to record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
SV-234517r1213158_ruleThe UEM server must be configured to record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.
SV-234520r1213160_ruleThe UEM server must prohibit user installation of software by an administrator without the appropriate assigned permission for software installation.
SV-234521r1213161_ruleThe UEM server must be configured to only allow enrolled devices that are compliant with UEM policies and assigned to a user in the application access group to download applications.
SV-234523r1213163_ruleThe UEM server must enforce access restrictions associated with changes to the server configuration.
SV-234524r1213164_ruleThe UEM server must audit the enforcement actions used to restrict access associated with changes to the application.
SV-234526r1213166_ruleThe UEM server must disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure.
SV-234538r1213177_ruleBefore establishing a connection to any endpoint device being managed, the UEM server must establish a trusted path between the server and endpoint that provides assured identification of the end point using a bidirectional authentication mechanism configured with a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the device.
SV-234543r1213182_ruleThe UEM server must prohibit the use of cached authenticators after an organization-defined time period.
SV-234544r1213183_ruleThe UEM server, for PKI-based authentication, must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.
SV-234555r1213194_ruleThe UEM server must configure web management tools with FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to protect the confidentiality of maintenance and diagnostic communications for nonlocal maintenance sessions.
SV-234556r1213195_ruleThe UEM server must verify remote disconnection when non-local maintenance and diagnostic sessions are terminated.
SV-234573r1213211_ruleThe UEM server must only allow the use of DoW PKI established certificate authorities for verification of the establishment of protected sessions.
SV-234574r1213212_ruleThe UEM server must be configured to use X.509v3 certificates for code signing for system software updates.
SV-234575r1213213_ruleThe UEM server must be configured to use X.509v3 certificates for code signing for integrity verification.
SV-234588r1213226_ruleThe UEM server must connect to [assignment: [list of applications]] and managed mobile devices with an authenticated and secure (encrypted) connection to protect the confidentiality and integrity of transmitted information.
SV-234596r1213234_ruleThe UEM server must be configured to write to the server event log when invalid inputs are received.
SV-234603r1213241_ruleThe UEM server must remove old software components after updated versions have been installed.
SV-234605r1213243_ruleThe UEM server must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).
SV-234622r1213259_ruleThe UEM server must be configured with the periodicity of the following commands to the agent of six hours or less: - query connectivity status; - query the current version of the managed device firmware/software; - query the current version of installed mobile applications; - read audit logs kept by the managed device.
SV-234623r1213260_ruleThe UEM server must run a suite of self-tests during initial start-up (power on) to demonstrate correct operation of the server.
SV-234624r1213261_ruleThe UEM server must alert the system administrator (SA) when anomalies in the operation of security functions are discovered.
SV-234629r1213266_ruleThe UEM server must be configured to verify software updates to the server using a digital signature mechanism prior to installing those updates.
SV-234642r1213279_ruleThe UEM server must generate audit records when successful/unsuccessful attempts to access security objects occur.
SV-234645r1213282_ruleThe UEM server must generate audit records when successful/unsuccessful attempts to modify privileges occur.
SV-234646r1213283_ruleThe UEM server must generate audit records when successful/unsuccessful attempts to modify security objects occur.
SV-234649r1213286_ruleThe UEM server must generate audit records when successful/unsuccessful attempts to delete privileges occur.
SV-234651r1213288_ruleThe UEM server must generate audit records when successful/unsuccessful attempts to delete security objects occur.
SV-234653r1213290_ruleThe UEM server must generate audit records when successful/unsuccessful logon attempts occur.
SV-234654r1213291_ruleThe UEM server must generate audit records for privileged activities or other system-level access.
SV-234655r1213292_ruleThe UEM server must generate audit records showing starting and ending time for user access to the system.
SV-234656r1213293_ruleThe UEM server must generate audit records when concurrent logons from different workstations occur.
SV-234657r1213294_ruleThe UEM server must generate audit records when successful/unsuccessful accesses to objects occur.
SV-234658r1213295_ruleThe UEM server must generate audit records for all direct access to the information system.
SV-234659r1213297_ruleThe UEM server must generate audit records for all account creations, modifications, disabling, and termination events.
SV-234664r1213302_ruleThe UEM server must use a FIPS-validated cryptographic module to generate cryptographic hashes.
SV-234665r1213303_ruleThe UEM server must, at a minimum, off-load audit logs of interconnected systems in real time and off-load standalone systems weekly.
SV-234666r1213306_ruleThe UEM server must be configured in accordance with the security configuration settings based on DoW security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
SV-234667r1213307_ruleThe UEM server must be configured to allow authorized administrators to read all audit data from audit records on the server.
SV-234668r1213308_ruleThe UEM server must be configured to implement FIPS 140-3 mode for all server and agent encryption.
SV-234669r1213309_ruleThe UEM server must be configured to prohibit client negotiation to TLS 1.2, SSL 2.0, or SSL 3.0.
SV-234673r1213313_ruleThe UEM server must authenticate endpoint devices (servers) before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
SV-234674r1213314_ruleIf cipher suites using pre-shared keys are used for device authentication, the UEM server must have a minimum security strength of 112 bits or higher.
SV-234676r1213316_ruleThe UEM server must validate certificates used for Transport Layer Security (TLS) functions by performing RFC 5280-compliant certification path validation.
SV-234677r1213317_ruleThe application must use FIPS-validated SHA-256 or higher hash function for digital signature generation and verification.
SV-256892r1213323_ruleThe UEM server must provide digitally signed policies and policy updates to the UEM agent.
SV-264368r1213324_ruleThe UEM server must sign policies and policy updates using a private key associated with [selection: an X509 certificate, a public key provisioned to the agent trusted by the agent] for policy verification.
SV-264369r1213325_ruleThe UEM server, for each unique policy managed, must validate the policy is appropriate for an agent using [selection: a private key associated with an X509 certificate representing the agent, a token issued by the agent] associated with a policy signing key uniquely associated with the policy.
SV-279012r1213326_ruleThe UEM server must be a version supported by the vendor.