STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 1 hour ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Ivanti MobileIron Sentry 9.x ALG Security Technical Implementation Guide

V-251023

CAT II (Medium)

The Sentry providing mobile device access control intermediary services must be configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or AAA server) which validate mobile device account access authorizations and privileges.

Rule ID

SV-251023r802291_rule

STIG

Ivanti MobileIron Sentry 9.x ALG Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000764

Discussion

User account and privilege validation must be centralized in order to prevent unauthorized access using changed or revoked privileges. ALGs can implement functions such as traffic filtering, authentication, access, and authorization functions based on computer and user privileges. However, the directory service (e.g., Active Directory or LDAP) must not be installed on the ALG, particularly if the gateway resides on the untrusted zone of the Enclave.

Check Content

Verify the MobileIron Core configured with the MobileIron Sentry is enabled with Active Directory or LDAP server. 

1. Log in to the MobileIron Core MIFS portal.
2. Go to Services >> LDAP.
3. Verify an LDAP server is configured and enabled.

If an LDAP server is not configured and enabled, this is a finding.

Fix Text

Ensure the MobileIron Core configured with the MobileIron Sentry is enabled with Active Directory or LDAP server. 

1. Log in to the MobileIron Core MIFS portal.
2. Go to Services >> LDAP.
3. Click "Add New".
4. Follow LDAP Configuration Wizard Prompts to enable an LDAP server (refer to the "Configuring LDAP Servers" section of the "Getting Started with MobileIron Core Guide" for more information).
5. Click "Save".