DoD Compliance · STIG

Omnissa WS1 UEM Agent Security Technical Implementation Guide

V1R1 · · · Released 26 May 2026 · 2 rules
Compare

Pick two releases to diff their requirements.

View

Open a previous version of this STIG.

This Security Technical Implementation Guide is published as a tool to improve the security of Department of War (DoW) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.
Supporting documents DISA companion ZIP · 2.5 MB 5 PDFs
Sort by
b
The Omnissa WS1 UEM Agent must be configured to enable the following function: Read audit logs of the managed endpoint device: Android.
AU-12 - Medium - CCI-000169 - V-284237 - SV-284237r1223978_rule
RMF Control
AU-12
Severity
M
CCI
CCI-000169
Version
OMW1-00-100350
Vuln IDs
  • V-284237
Rule IDs
  • SV-284237r1223978_rule
Audit logs and alerts enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify when the security posture of the device is not as expected. This enables the UEM administrator to take an appropriate remedial action. Satisfies: FMT_SMF_EXT.4.1 Reference: PP-UEM-401005 Satisfies: SRG-APP-000089-UEM-100012, SRG-APP-000358-UEM-100013
Checks: C-88801r1211874_chk

Review the MDM Agent documentation and configuration settings to determine if the following function is enabled: Read audit logs of the MD. This validation procedure is performed on the MDM Administration Console. On the MDM console, do the following: 1. Authenticate to the Workspace ONE UEM console as the administrator. 2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy. Enable "Request Device Log" in the privacy settings. If "Request Device Log" is present, then no device log is being requested from the MD, and this is a finding.

Fix: F-88706r1211875_fix

Configure the MDM Agent to enable the following function: Read audit logs of the MD. On the MDM console, do the following: 1. Authenticate to the Workspace ONE UEM console as the administrator. 2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy. Enable "Request Device Log" in the privacy settings. 3. Select "Save".

b
The Omnissa WS1 UEM Agent must be configured to perform one of the following actions upon an attempt to unenroll the mobile device from management: - Prevent the unenrollment from occurring. - Wipe the device to factory default settings. - Wipe the work profile with all associated applications and data.
CM-6 - Medium - CCI-000366 - V-284246 - SV-284246r1223987_rule
RMF Control
CM-6
Severity
M
CCI
CCI-000366
Version
OMW1-00-101300
Vuln IDs
  • V-284246
Rule IDs
  • SV-284246r1223987_rule
Access control of mobile devices to DoW sensitive information or access to DoW networks must be controlled so that DoW data will not be compromised. The primary method of access control of mobile devices is via enrollment of authorized mobile devices on the UEM server. Therefore, the UEM server must have the capability to enforce a policy for this control. Satisfies: FMT_UNR_EXT.1.1
Checks: C-88810r1211877_chk

Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings. If "Block User Unenrollment" is not "Enabled", this is a finding. Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment. Edit the DEP profile and navigate to "MDM features". If "Lock MDM Profile" is not "Enabled", this is a finding.

Fix: F-88715r1211878_fix

Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings. Find "Block User Unenrollment" and choose "Enabled". Click "Save". Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment. Edit the DEP profile and navigate to "MDM features". Choose "Enabled" for "Lock MDM Profile". Click "Save".