Omnissa WS1 UEM Agent Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 5 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- OMW1-00-100350
- Vuln IDs
-
- V-284237
- Rule IDs
-
- SV-284237r1223978_rule
Checks: C-88801r1211874_chk
Review the MDM Agent documentation and configuration settings to determine if the following function is enabled: Read audit logs of the MD. This validation procedure is performed on the MDM Administration Console. On the MDM console, do the following: 1. Authenticate to the Workspace ONE UEM console as the administrator. 2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy. Enable "Request Device Log" in the privacy settings. If "Request Device Log" is present, then no device log is being requested from the MD, and this is a finding.
Fix: F-88706r1211875_fix
Configure the MDM Agent to enable the following function: Read audit logs of the MD. On the MDM console, do the following: 1. Authenticate to the Workspace ONE UEM console as the administrator. 2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy. Enable "Request Device Log" in the privacy settings. 3. Select "Save".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- OMW1-00-101300
- Vuln IDs
-
- V-284246
- Rule IDs
-
- SV-284246r1223987_rule
Checks: C-88810r1211877_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings. If "Block User Unenrollment" is not "Enabled", this is a finding. Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment. Edit the DEP profile and navigate to "MDM features". If "Lock MDM Profile" is not "Enabled", this is a finding.
Fix: F-88715r1211878_fix
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings. Find "Block User Unenrollment" and choose "Enabled". Click "Save". Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment. Edit the DEP profile and navigate to "MDM features". Choose "Enabled" for "Lock MDM Profile". Click "Save".