CCI-000765
Implement multifactor authentication for network access to privileged accounts.
1 rule found Severity: High

1 rule found Severity: High

1 rule found Severity: High

The DBN-6300 must use multifactor authentication for network access (remote and nonlocal) to privileged accounts.
1 rule found Severity: Medium

The HYCU VM console and HYCU Web UI must be configured to use an authentication server for authenticating users prior to granting access to protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined requirements.
1 rule found Severity: High

The MQ Appliance network device must use multifactor authentication for network access to privileged accounts.
1 rule found Severity: Medium

The WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.
1 rule found Severity: Medium

The Ivanti MobileIron Core server must be configured to use a DoD Central Directory Service to provide multifactor authentication for network access to privileged and non-privileged accounts.
1 rule found Severity: Medium

MobileIron Sentry must be configured to use DoD PKI as multi-factor authentication (MFA) for interactive logins.
1 rule found Severity: High

Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts.
1 rule found Severity: High

Common Access Card (CAC)-based authentication must be enforced and enabled on the Tanium Server for network and local access with privileged and non-privileged accounts.
1 rule found Severity: High

Common Access Card (CAC)-based authentication must be enabled on the Tanium Server for network access with privileged accounts.
1 rule found Severity: High

Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1 rule found Severity: Medium

Multi-factor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1 rule found Severity: Medium

The Tanium Operating System (TanOS) must use multifactor authentication for network access to privileged accounts.
2 rules found Severity: High

The NSX-T Manager must integrate with either VMware Identity Manager (vIDM) or VMware Workspace ONE Access.
1 rule found Severity: High

The Ubuntu operating system must implement smart card logins for multifactor authentication for access to accounts.
1 rule found Severity: Medium

2 rules found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

The Ubuntu operating system must implement smart card logins for multifactor authentication for local and network access to privileged and nonprivileged accounts.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to use multifactor authentication (MFA) for interactive logins.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: High

The ICS must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins.
1 rule found Severity: High

The Ivanti EPMM server must be configured to use a DoD Central Directory Service to provide multifactor authentication for network access to privileged and non-privileged accounts.
1 rule found Severity: Medium

Sentry must be configured to use DOD PKI as multi-factor authentication (MFA) for interactive logins.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

Microsoft Intune service must be configured to use a DOD Central Directory Service to provide multifactor authentication for network access to privileged and nonprivileged accounts and individual and group accounts.
1 rule found Severity: Medium

Windows 11 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.
1 rule found Severity: Medium

The Windows PAW must be configured to enforce two-factor authentication and use Active Directory for authentication management.
1 rule found Severity: Medium

Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication.
1 rule found Severity: Medium

1 rule found Severity: High

The network device must be configured to use DoD PKI as multi-factor authentication (MFA) for interactive logins.
1 rule found Severity: High

1 rule found Severity: Medium

The Oracle Linux operating system must uniquely identify and must authenticate organizational users (or processes acting on behalf of organizational users) using multifactor authentication.
1 rule found Severity: Medium

1 rule found Severity: Medium

SLEM 5 must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
1 rule found Severity: Medium

Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1 rule found Severity: Medium

Multifactor authentication must be enabled on the Tanium Server for network access with privileged accounts.
1 rule found Severity: High

TOSS must use multifactor authentication for network and local access to privileged and nonprivileged accounts.
1 rule found Severity: Medium

1 rule found Severity: Medium

AAA Services must be configured to require multifactor authentication using Personal Identity Verification (PIV) credentials for authenticating privileged user accounts.
1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

The macOS system must enforce multifactor authentication for privilege escalation through the sudo command.
2 rules found Severity: Medium

The application server must use multifactor authentication for network access to privileged accounts.
1 rule found Severity: High

1 rule found Severity: High

The application must use multifactor (Alt. Token) authentication for network access to privileged accounts.
1 rule found Severity: Medium

The application must use multifactor (Alt. Token) authentication for local access to privileged accounts.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must implement smart card logins for multifactor authentication for local and network access to privileged and nonprivileged accounts.
1 rule found Severity: Medium

The Central Log Server must use multifactor authentication for network access to privileged user accounts.
1 rule found Severity: Medium

The Central Log Server must use multifactor authentication for local access using privileged user accounts.
1 rule found Severity: Medium

The container platform must use multifactor authentication for network access to privileged accounts.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Dell OS10 Switch must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

AOS must be configured to use DOD public key infrastructure (PKI) as multifactor authentication (MFA) for interactive logins.
1 rule found Severity: High

The HYCU virtual appliance must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins.
1 rule found Severity: High

The Mainframe Product must use multifactor authentication for network access to privileged accounts.
1 rule found Severity: Medium

1 rule found Severity: Medium

Windows 10 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.
1 rule found Severity: Medium

Access to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 8 must implement smart card logon for multifactor authentication for access to interactive accounts.
1 rule found Severity: Medium

The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
2 rules found Severity: Medium

Samsung Android must be configured to enable a screen-lock policy that will lock the display after a period of inactivity - Disable trust agents.
6 rules found Severity: Medium

Samsung Android must be configured to disable authentication mechanisms providing user access to protected data other than a Password Authentication Factor: Face recognition.
4 rules found Severity: Medium

Samsung Android must be configured to disable authentication mechanisms providing user access to protected data other than a Password Authentication Factor, including face recognition.
2 rules found Severity: Medium

The UEM server must be configured to use a DoD Central Directory Service to provide multifactor authentication for network access to privileged and non-privileged accounts.
1 rule found Severity: Medium

All UEM server local accounts created during application installation and configuration must be removed. Note: In this context local accounts refers to user and or administrator accounts on the server that use user name and password for user access and authentication.
1 rule found Severity: Medium

The NSX Manager must be configured to integrate with an identity provider that supports multifactor authentication (MFA).
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

Rancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
1 rule found Severity: High
