Rule ID
SV-251023r1028189_rule
Version
V3R1
CCIs
User account and privilege validation must be centralized in order to prevent unauthorized access using changed or revoked privileges. ALGs can implement functions such as traffic filtering, authentication, access, and authorization functions based on computer and user privileges. However, the directory service (e.g., Active Directory or LDAP) must not be installed on the ALG, particularly if the gateway resides on the untrusted zone of the Enclave.
Verify the MobileIron Core configured with the Sentry is enabled with Active Directory or LDAP server. 1. Log in to the MobileIron Core MIFS portal. 2. Go to Services >> LDAP. 3. Verify an LDAP server is configured and enabled. If an LDAP server is not configured and enabled, this is a finding.
Ensure the MobileIron Core configured with the Sentry is enabled with Active Directory or LDAP server. 1. Log in to the MobileIron Core MIFS portal. 2. Go to Services >> LDAP. 3. Click "Add New". 4. Follow LDAP Configuration Wizard Prompts to enable an LDAP server (refer to the "Configuring LDAP Servers" section of the "Getting Started with MobileIron Core Guide" for more information). 5. Click "Save".