STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 6 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Unified Endpoint Management Agent Security Requirements Guide

V-234235

CAT II (Medium)

The UEM Agent must provide an alert via the trusted channel to the UEM Server in the event of any of the following audit events: -successful application of policies to a mobile device -receiving or generating periodic reachability events -change in enrollment state -failure to install an application from the UEM Server -failure to update an application from the UEM Server.

Rule ID

SV-234235r960879_rule

STIG

Unified Endpoint Management Agent Security Requirements Guide

Version

V2R1

CCIs

CCI-000169

Discussion

Alerts providing notification of a change in enrollment state facilitate verification of the correct operation of security functions. When an UEM server receives such an alert from an UEM Agent, it indicates the security policy may no longer be enforced on the mobile device. This enables the UEM administrator to take an appropriate remedial action. Satisfies: FAU_ALT_EXT.2.1 Reference: PP-UEM-402001, PP-UEM-402002, PP-MDM-402003

Check Content

Verify the UEM Agent provides an alert via the trusted channel to the UEM Server in the event of any of the following audit events:
-successful application of policies to a mobile device
-receiving or generating periodic reachability events 
-change in enrollment state
-failure to install an application from the UEM Server
-failure to update an application from the UEM Server.

If the UEM Agent does not provide an alert via the trusted channel to the UEM Server in the event of any of the following audit events:
-successful application of policies to a mobile device 
-receiving or generating periodic reachability events 
-change in enrollment state
-failure to install an application from the UEM Server
-failure to update an application from the UEM Server
this is a finding.

Fix Text

Configure the UEM Agent to provide an alert via the trusted channel to the UEM Server in the event of any of the following audit events:
-successful application of policies to a mobile device 
-receiving or generating periodic reachability events 
-change in enrollment state
-failure to install an application from the UEM Server
-failure to update an application from the UEM Server.