The UEM server must prohibit the use of cached authenticators after an organization-defined time period.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-234543SRG-APP-000400SRG-APP-000400-UEM-000271SV-234543r961521_rule2024-12-092
Description
If cached authentication information is out-of-date, the validity of the authentication information may be questionable. According to the CNSS 1253, the IA-5(13) control which is tied to this requirement is not defined at the DoD-level. The organization should specify this value based on numerous factors, including the application in question, the data it hosts and the associated exposures/risks.
ℹ️ Check
Requirement is Not Applicable when the UEM server is configured to use DoD Central Directory Service for administrator account authentication. Verify the UEM server prohibits the use of cached authenticators after an organization-defined time period. If the UEM server does not prohibit the use of cached authenticators after an organization-defined time period, this is a finding.
✔️ Fix
Configure the UEM server to prohibit the use of cached authenticators after an organization-defined time period.