Rule version AWTM-NM-000013 · STIG v1 · 2026-09-14
The purpose of requiring a device that is separate from the system to which the user is attempting to gain access for one of the factors during MFA is to reduce the likelihood of compromising authenticators or credentials stored on the system. Adversaries may be able to compromise such authenticators or credentials and subsequently impersonate authorized users. Implementing one of the factors on a separate device (e.g., a hardware token), provides a greater strength of mechanism and an increased level of assurance in the authentication process.
Satisfies: SRG-APP-000820-NDM-000170, SRG-APP-000153-NDM-000249, SRG-APP-000080-NDM-000220, SRG-APP-000231-NDM-000271, SRG-APP-000825-NDM-000180, SRG-APP-000033-NDM-000212, SRG-APP-000121-NDM-000238, SRG-APP-000122-NDM-000239, SRG-APP-000149-NDM-000247, SRG-APP-000516-NDM-000336, SRG-APP-000119-NDM-000236, SRG-APP-000156-NDM-000250
1. Log in to the WTM Web UI. 2. Verify the "SAML Login" is present. 3. Click "SAML Login", to be redirected to the ADFS server logon page. 4. Select the CAC/AltToken certificate and log in. 5. Navigate to Admin >> User Management >> Multifactor Auth. 6. Verify that Mode is set to "both" and the ADFS server is configured to meet DoW requirements.
If the Mode shows disabled or an ADFS server is not configured, this is a finding.
WTM Web UI: 1. Log in to the WTM Web UI. 2. Navigate to Admin >> User Management >> Multifactor Auth. 3. Under mode, select both. 4. Under "Provider ID", type the URL of the Active Directory Federated Services (ADFS) server (e.g., http://adfs.dow.mil/adfs/services/trust). 5. Under "Sign On URL", enter the URL of the ADFS sign-on URL (e.g., https://adfs.dow.mil/adfs/ls/). 6. Under "Sign Out URL", enter the URL of the ADFS sign-out URL. In most cases, the sign-on and sign-out URLs are the same (e.g., https://adfs.dow.mil/adfs/ls/). 7. Enter a "Max Clock Skew (s)" of 10 or greater. 8. Copy and paste the ADFS signing certificate in the block for "Provider Certificate". This is the certificate the ADFS server uses to sign the SAML tokens. This is not an encryption certificate. 9. Under "Relying Party ID", enter the URL of the WTM web UI (e.g., https://wtm.dow.mil). 10. Click "Commit". 11. Under the block for "ADFS Setup", copy all the information to be used on the ADFS server configuration in the next steps. 12. Click "Logout".
ADFS Server: 1. Log in to the ADFS server. 2. Under "Relying Party Trusts", create new. 3. Select "Claims Aware". 4. Select "Enter data manually". 5. Add a name, preferably add the FQDN with https (e.g., https://wtm.dow.mil). 6. Click "Enable support for SAML 2.0" and add the service URL (e.g., add the same URL but add /saml/consume at the end, such as https://wtm.dow.mil/saml/consume). 7. Add the relying party ID, the URL https://wtm.dow.mil. 8. Permit everyone. 9. Click "Next" and then "Next" again to configure the claims. a. Add the "LDAP Attribute As Claim" for User-Principal-Name (UPN) inside the attribute store AD as Name ID. b. Add a new "Send Group Membership as a Claim". c. For operator, add the Operator group. The outgoing claim type is "Role", and outgoing claim value is "Oper". d. For admin, add the Admins group. The outgoing claim type is "Role", and outgoing claim value is "admin". e. For security, add the Security group. The outgoing claim type is "Role", and outgoing claim value is "security".
Log back in to the WTM Web UI. There should now be a "SAML Login" button. 1. Click "SAML Login", to be redirected to the ADFS server logon page. 2. Select the CAC/AltToken certificate. This should result in a successful login. 3. Check the logs for any login issues or exceptions.