STIGQter STIGQter: STIG Summary: MobileIron Core v10.x MDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 15 Feb 2019:

The MobileIron Core v10 server must be configured to have at least one user in the following Administrator roles: Server primary administrator, security configuration administrator, device user group administrator, auditor.

DISA Rule

SV-101919r1_rule

Vulnerability Number

V-91817

Group Title

PP-MDM-311058

Rule Version

MICR-10-000590

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the MDM server with the Administrator roles:
- Server primary administrator
- Security configuration administrator
- Device user group administrator
- Auditor

On the MDM console, do the following:
1. Follow the instructions in the "MobileIron Core and Android Client Mobile Device Management Protection Profile Guide" in section "Configuring administrators to have roles defined by federal requirements":
a. Follow the instructions for "Configuring administrators to be a server primary administrator".
b. Follow the instructions for "Configuring administrators to be a security configuration administrator".
c. Follow the instructions for "Configuring administrators to be a device user group administrator".
d. Follow the instructions for "Configuring administrators to be an auditor".
2. In each case instructions are provided to create a new user with the identified role.

Check Contents

Review the MDM server configuration settings and verify the server is configured with the Administrator roles:
- Server primary administrator
- Security configuration administrator
- Device user group administrator
- Auditor

On the MDM console, do the following:
1. Verify a user is in the "Server primary administrator" role.
a. Logon to the MobileIron Core Server system manager portal as a user with the "server primary administrator" role using a web browser.
b. Select Security >> Identity Source >> Local Users.

If a user in the "server primary administrator" role is not listed, this is a finding.

2. Verify a user is in the "Security configuration administrator" role.
a. Logon to the MobileIron Core Server administrator portal as a user with the "server primary administrator" role using a web browser.
b. Select Admin >> Admins.
c. Select user with the "Security configuration administrator" role.
d. Click Actions >> Edit Roles.
e. Verify that the following roles are selected: "Manage label", "View user", "Manage app", "Manage configuration", "Manage policy", "Manage settings and services", and "Manage administrators and device" spaces.

If the "Security configuration administrator" user is not found or any of the required roles are not selected, this is a finding.

3. Verify a user is in the "Device user group administrator" role.
a. Logon to the MobileIron Core Server administrator portal as a user with the "server primary administrator" role using a web browser.
b. Select Admin >> Admins.
c. Select user with the "Device user group administrator" role.
d. Click Actions >> Edit Roles.
e. Verify that the following roles are selected: "wipe devices", "add device", "manage ActiveSync device", and "delegate retired device" roles.

If the "Device user group administrator" user is not found or any of the required roles are not selected, this is a finding.

4. Verify a user is in the "Auditor" role.
a. Logon to the MobileIron Core Server administrator portal as a user with the "server primary administrator" role using a web browser.
b. Select Admin >> Admins.
c. Select user with the "Device user group administrator" role.
d. Click Actions >> Edit Roles.
e. Check that the following roles are selected: "Manage logs and events".

If the user is not found or any of the required roles are not selected, this is a finding.

Vulnerability Number

V-91817

Documentable

False

Rule Version

MICR-10-000590

Severity Override Guidance

Review the MDM server configuration settings and verify the server is configured with the Administrator roles:
- Server primary administrator
- Security configuration administrator
- Device user group administrator
- Auditor

On the MDM console, do the following:
1. Verify a user is in the "Server primary administrator" role.
a. Logon to the MobileIron Core Server system manager portal as a user with the "server primary administrator" role using a web browser.
b. Select Security >> Identity Source >> Local Users.

If a user in the "server primary administrator" role is not listed, this is a finding.

2. Verify a user is in the "Security configuration administrator" role.
a. Logon to the MobileIron Core Server administrator portal as a user with the "server primary administrator" role using a web browser.
b. Select Admin >> Admins.
c. Select user with the "Security configuration administrator" role.
d. Click Actions >> Edit Roles.
e. Verify that the following roles are selected: "Manage label", "View user", "Manage app", "Manage configuration", "Manage policy", "Manage settings and services", and "Manage administrators and device" spaces.

If the "Security configuration administrator" user is not found or any of the required roles are not selected, this is a finding.

3. Verify a user is in the "Device user group administrator" role.
a. Logon to the MobileIron Core Server administrator portal as a user with the "server primary administrator" role using a web browser.
b. Select Admin >> Admins.
c. Select user with the "Device user group administrator" role.
d. Click Actions >> Edit Roles.
e. Verify that the following roles are selected: "wipe devices", "add device", "manage ActiveSync device", and "delegate retired device" roles.

If the "Device user group administrator" user is not found or any of the required roles are not selected, this is a finding.

4. Verify a user is in the "Auditor" role.
a. Logon to the MobileIron Core Server administrator portal as a user with the "server primary administrator" role using a web browser.
b. Select Admin >> Admins.
c. Select user with the "Device user group administrator" role.
d. Click Actions >> Edit Roles.
e. Check that the following roles are selected: "Manage logs and events".

If the user is not found or any of the required roles are not selected, this is a finding.

Check Content Reference

M

Target Key

3433

Comments