UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The Ivanti MobileIron Core server must prohibit password reuse for a minimum of four generations.


Overview

Finding ID Version Rule ID IA Controls Severity
V-251408 IMIC-11-004950 SV-251408r985820_rule Medium
Description
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. To meet password policy requirements, passwords need to be changed at specific policy-based intervals. If the information system or application allows the user to consecutively reuse their password when that password has exceeded its defined lifetime, the end result is a password that is not changed as per policy requirements. Satisfies: FMT_SMF.1(2)b Reference: PP-MDM-431025
STIG Date
Ivanti MobileIron Core MDM Server Security Technical Implementation Guide 2024-05-23

Details

Check Text ( C-54843r985818_chk )
Verify Core is configured to enforce password history reuse of four last passwords:

1. Log in to the Core console.
2. Security >> Password Policy.
3. Verify "Enforce Password History (Last 4 passwords)" is enabled.

If "Enforce Password History (Last 4 passwords)" is not enabled, this is a finding.
Fix Text (F-54796r985819_fix)
Configure Core to enforce password history reuse of four last passwords:

1. Log in to the Core console.
2. Security >> Password Policy.
3. Check "Enable" for "Enforce Password History (Last 4 passwords)".