Omnissa WS1 UEM Server Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 5 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- OMW1-00-000100
- Vuln IDs
-
- V-284249
- Rule IDs
-
- SV-284249r1223990_rule
Checks: C-88813r1211886_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Session Management. If "Allow Multiple Sessions" is not "Disabled", this is a finding. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88718r1211944_fix
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Session Management. Next to "Allow Multiple Sessions", click "Disabled". Click "Save". Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- OMW1-00-000300
- Vuln IDs
-
- V-284251
- Rule IDs
-
- SV-284251r1223992_rule
Checks: C-88815r1211889_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Session Management. If "Idle Session Timeout" is not set to 15 minutes or less, this is a finding. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88720r1211890_fix
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Session Management. Next to "Idle Session Timeout" enter "15". Click "Save". Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000015
- Version
- OMW1-00-000600
- Vuln IDs
-
- V-284254
- Rule IDs
-
- SV-284254r1223995_rule
Checks: C-88818r1211929_chk
1. Verify directory service integration. a. Authenticate to the Workspace ONE UEM console as an administrator. b. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Directory Services. Select "Skip wizard and configure manually". c. Under the "Server" tab, verify directory service connection information. If no valid directory service is configured, this is a finding. In the bottom right, click "Test Connection". If the test is not successful, this is a finding. 2. Validate that device enrollment uses directory service authentication only. a. Navigate to Groups & Settings >> All Settings >> Devices and Users >> General >> Enrollment. b. Under the "Authentication" tab, find the "Authentication Modes" setting. If "Directory" is not the one and only checked box, this is a finding. 3. Validate there is only one "break-glass" local admin configured. a. Navigate to Accounts >> Administrators >> List View. b. Review account types under the "Admin Type" column. If any users have an "Admin Type" of "Basic", outside of a single "break-glass" admin, this is a finding. 4. Validate that all users are centrally managed by a directory service. a. Navigate to Accounts >> Users >> List View. b. Click "Layout" and select "Custom". c. Under the "Security Type" column, if any "Basic" accounts are listed, this is a finding.
Fix: F-88723r1211953_fix
1. Set up directory service integration. a. Authenticate to the Workspace ONE UEM console as an administrator. b. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Directory Services. Select "Skip wizard and configure manually". c. Under the "Server" tab, complete the directory service connection information. This will be site-specific. Consult Omnissa documentation for "Directory Services Setup" for details. d. Click "Save". 2. Require that device enrollment only uses directory service authentication. a. Navigate to Groups & Settings >> All Settings >> Devices and Users >> General >> Enrollment. b. Under the "Authentication" tab, find the "Authentication Modes" setting. c. Ensure that "Directory" is the one and only checked box. d. Click "Save". 3. Remove all admin accounts that are not the "break-glass" account. a. Navigate to Accounts >> Administrators >> List View. b. For each user with an "Admin Type" of "Basic" that is NOT the "break-glass" account, select the three vertical dots next to that user and then select "Delete". c. Click "Delete" when prompted to confirm. 4. Remove all users that are not centrally managed by a directory service. a. Navigate to Accounts >> Users >> List View. b. Click "Layout" and select "Custom". c. For each user with a "Security Type" of "Basic", select the checkbox next to the user. d. Click "More Actions", then click "Delete". e. To confirm, click "Save" when prompted.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- OMW1-00-001300
- Vuln IDs
-
- V-284260
- Rule IDs
-
- SV-284260r1224001_rule
Checks: C-88824r1211895_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. If "Maximum invalid login attempts" is not set to "3", this is a finding. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88729r1211896_fix
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. Next to "Maximum invalid login attempts", enter "3". Click "Save". Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000139
- Version
- OMW1-00-002900
- Vuln IDs
-
- V-284275
- Rule IDs
-
- SV-284275r1224016_rule
Checks: C-88839r1211956_chk
Authenticate to the Workspace ONE UEM console as an administrator. Click the administrator's name in the top right to expose a drop-down menu. Select Manage Account Settings >> Notifications. If the radio button for "Logging Server Failure" is not set to "Console and Email", this is a finding. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88744r1211957_fix
Authenticate to the Workspace ONE UEM console as an administrator. 1. Click the administrator's name in the top right to expose a drop-down menu. Select Manage Account Settings >> Notifications. 2. Toggle the radio button for "Console and Email" next to "Logging Server Failure". 3. Enter an email to send the alert to (typically the Security Operations Center [SOC] or group distro). 4. Click "Save". Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- OMW1-00-003700
- Vuln IDs
-
- V-284282
- Rule IDs
-
- SV-284282r1224025_rule
Checks: C-88846r1224023_chk
Review the MDM server platform configuration to determine whether a DoW-approved firewall is installed or if the platform operating system provides a firewall service that can restrict both inbound and outbound traffic by Transmission Control Protocol (TCP)/User Datagram Protocol (UDP) port and Internet Protocol (IP) address. If there is not a host-based firewall present on the MDM server platform, or if it is not configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, this is a finding.
Fix: F-88751r1224024_fix
Install and configure a DoW-approved firewall to protect the network segment on which the Workspace ONE UEM server is installed.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000765
- Version
- OMW1-00-004020
- Vuln IDs
-
- V-284284
- Rule IDs
-
- SV-284284r1224027_rule
Checks: C-88848r1211902_chk
Authenticate to the Workspace ONE UEM console as an administrator. 1. Navigate to Accounts >> Administrators >> List View. 2. For each account with an "Admin Type" of "Basic", click the three vertical dots next to the account name and select "Edit". 3. Click "Next" three times to reach the "Settings" page. If "Two Factor Authentication" is not enabled, this is a finding. If the account has the "Read Only" role and is used for automation such as compliance scanning, this is not applicable to that account.
Fix: F-88753r1211903_fix
Authenticate to the Workspace ONE UEM console as an administrator. 1. Navigate to Accounts >> Administrators >> List View. 2. For each account with an "Admin Type" of "Basic", click the three vertical dots next to the account name and select "Edit". 3. Click "Next" three times to reach the "Settings" page. 4. Enable "Two Factor Authentication" and configure either email or SMS notification. 5. Click "Save". Note: The OTP code will be sent to the email or mobile phone configured on the previous pages. Ensure they are configured correctly. Note: The only authorized local account is the "break-glass" account.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- OMW1-00-006500
- Vuln IDs
-
- V-284305
- Rule IDs
-
- SV-284305r1224048_rule
Checks: C-88869r1211905_chk
Review the Workspace ONE UEM server configuration settings and verify the server is configured to transfer Workspace ONE UEM server logs to another server for storage, analysis, and reporting. On the MDM console, do the following: 1. Authenticate to the Workspace ONE UEM console as the administrator. 2. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Syslog. 3. If "Syslog Integration" is set to "DISABLED", this is a finding. 4. Examine the syslog configuration (server hostname, protocol, port, syslog facility, message tag, message content) for conformance with operational standards. If any are not set according to the standards, this is a finding. Note: Workspace ONE UEM server logs include logs of MDM events and logs transferred to the Workspace ONE UEM server by MDM agents of managed devices.
Fix: F-88774r1211906_fix
Configure the Workspace ONE UEM server to transfer Workspace ONE UEM server logs to another server for storage, analysis, and reporting. On the MDM console, do the following: 1. Authenticate to the Workspace ONE UEM console as the administrator. 2. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Syslog. 3. Set "Syslog Integration" to "ENABLED". 4. Configure syslog server hostname, protocol, port, syslog facility, message tag, message content according to organizational standards. 5. Click "SAVE". 6. Verify changes save successfully and Workspace ONE UEM server can transfer audit logs to the new syslog server.
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-001890
- Version
- OMW1-00-006600
- Vuln IDs
-
- V-284306
- Rule IDs
-
- SV-284306r1224049_rule
Checks: C-88870r1211908_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Syslog. If "Syslog Format" is not set to "RFC-5424 Format", this is a finding.
Fix: F-88775r1211961_fix
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> System >> Enterprise Integration >> Syslog. Next to "Syslog Format" select "RFC-5424 Format" from the drop-down menu. Click "Save".
- RMF Control
- SI-6
- Severity
- M
- CCI
- CCI-002696
- Version
- OMW1-00-008200
- Vuln IDs
-
- V-284320
- Rule IDs
-
- SV-284320r1224063_rule
Checks: C-88884r1211963_chk
Review the Workspace ONE UEM server for a periodicity for reachable events of six hours or less for the following commands to the agent: - Query connectivity status. - Query the current version of the mobile device firmware/software. - Query the current version of installed mobile applications. On the MDM console, do the following: 1. Authenticate to the Workspace ONE UEM console as the administrator. 2. Navigate to Groups & Settings >> All Settings. 3. Under the "Devices & Users" heading: For Android, choose Android >> Intelligent Hub Settings. a. Under the "General" heading, if "Heartbeat Interval" is set to more than six hours, this is a finding. This setting handles querying of connectivity status and current version of mobile device firmware/software. b. Under the "Application List" heading, if the "Application List Interval" is set to more than 360 minutes, this is a finding. This setting handles querying for the current version of installed mobile applications. For iOS choose Apple >> MDM Sample Schedule. a. If "Device Information Sample" is set to more than six hours, this is a finding. This setting handles querying of connectivity status and current version of mobile device firmware/software. b. If "Application List Sample" and "Managed App List Sample" are set to more than six hours, this is a finding. This setting handles querying for the current version of installed mobile applications. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88789r1211964_fix
Configure the Workspace ONE UEM server with a periodicity for reachable events of six hours or less for the following commands to the agent: - Query connectivity status. - Query the current version of the MD firmware/software. - Query the current version of installed mobile applications. On the MDM console, do the following: 1. Authenticate to the Workspace ONE UEM console as the administrator. 2. Navigate to Groups & Settings >> All Settings. 3. Under the "Devices & Users" heading: For Android, choose Android >> Intelligent Hub Settings. a. To modify any settings, click "Override". b. Under the "General" heading, set "Heartbeat Interval" using the drop-down, if necessary. This setting handles querying of connectivity status and current version of mobile device firmware/software. c. Under the "Application List" heading, set the "Application List Interval", as necessary, to the appropriate number of minutes. There is no control for periodicity of reading audit logs. They are sent to the server automatically. For iOS, choose Apple >> MDM Sample Schedule. a. To modify any settings, click "Override". b. Set "Device Information Sample", as necessary, to the appropriate number of hours. This will control periodicity of both querying connectivity and querying the current version of mobile device firmware/software. Querying of installed mobile applications is controlled by both "Application List Sample" and "Managed App List Sample" fields. "Application List Sample" requests all the apps on the device (managed and unmanaged), whereas "Managed App List Sample" only returns MDM installed apps. Both samples return app versions. There is no control for periodicity of reading audit logs. They are sent to the server automatically. Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- OMW1-00-011400
- Vuln IDs
-
- V-284349
- Rule IDs
-
- SV-284349r1224092_rule
Checks: C-88913r1211914_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. If "Minimum Password Length" is not set to "15", this is a finding. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88818r1211915_fix
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. Configure "Minimum Password Length" to "15". Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- Severity
- M
- CCI
- CCI-004061
- Version
- OMW1-00-011500
- Vuln IDs
-
- V-284350
- Rule IDs
-
- SV-284350r1224093_rule
Checks: C-88914r1211917_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. If "Enforced password history" is not set to "5 passwords remembered", this is a finding. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88819r1211918_fix
Authenticate to the Workspace ONE UEM console as an administrator. 1. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. 2. Configure "Enforced password history" to "5 passwords remembered". 3. Click "Save". Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- OMW1-00-011600
- Vuln IDs
-
- V-284351
- Rule IDs
-
- SV-284351r1224094_rule
Checks: C-88915r1211920_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. If "Password complexity level" is not set to "Mixed case, alphabetic, numeric and special characters", this is a finding. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88820r1211966_fix
Authenticate to the Workspace ONE UEM console as an administrator. 1. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. 2. Configure "Password complexity level" to "Mixed case, alphabetic, numeric and special characters". 3. Click "Save". Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- OMW1-00-012200
- Vuln IDs
-
- V-284354
- Rule IDs
-
- SV-284354r1224097_rule
Checks: C-88918r1211923_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. If "Password Expiration Period (days)" is not set to "60" (or less), this is a finding. Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.
Fix: F-88823r1211924_fix
Authenticate to the Workspace ONE UEM console as an administrator. 1. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. 2. Configure "Password Expiration Period (days)" to "60" or less. 3. Click "Save". Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- OMW1-00-013100
- Vuln IDs
-
- V-284358
- Rule IDs
-
- SV-284358r1224101_rule
Checks: C-88922r1211926_chk
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Accounts >> Administrators >> Admin Roles. From the Roles page, locate the following predefined roles: - AirWatch Administrator. - Device Manager. - Read Only. If any role above does not have at least one member, this is a finding. If the "AirWatch Administrator" and "Device Manager" roles are not restricted to the smallest possible set of administrators following least privilege principles, this is a finding. If any of these predefined roles were removed in favor of org-defined roles, ensure that these new roles duplicate the functionality of the default roles, as described in the discussion. If they do not, this is a finding.
Fix: F-88827r1211927_fix
Authenticate to the Workspace ONE UEM console as an administrator. Navigate to Accounts >> Administrators >> Admin Roles. From the Roles page, locate the following predefined roles: - AirWatch Administrator. - Device Manager. - Read Only. Ensure that at least one user exists in each group or the org-defined replacement roles. Ensure that the "AirWatch Administrator" and "Device Manager" roles are restricted to the smallest possible set of administrators following least privilege principles.