STIGUI
V-284246CAT II — Medium severitySV-284246r1223987_rule

The Omnissa WS1 UEM Agent must be configured to perform one of the following actions upon an attempt to unenroll the mobile device from management: - Prevent the unenrollment from occurring. - Wipe the device to factory default settings. - Wipe the work profile with all associated applications and data.

Rule version OMW1-00-101300 · STIG v1 · 2026-06-15

Discussion

Access control of mobile devices to DoW sensitive information or access to DoW networks must be controlled so that DoW data will not be compromised. The primary method of access control of mobile devices is via enrollment of authorized mobile devices on the UEM server. Therefore, the UEM server must have the capability to enforce a policy for this control.

Satisfies: FMT_UNR_EXT.1.1

Check

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings.

If "Block User Unenrollment" is not "Enabled", this is a finding.

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment.

Edit the DEP profile and navigate to "MDM features". If "Lock MDM Profile" is not "Enabled", this is a finding.

Fix

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Android >> Intelligent Hub Settings.

Find "Block User Unenrollment" and choose "Enabled". Click "Save".

Navigate to Groups & Settings >> All Settings >> Devices & Users >> Apple >> Automated Device Enrollment.

Edit the DEP profile and navigate to "MDM features". Choose "Enabled" for "Lock MDM Profile". Click "Save".

Identifiers

Group ID
V-284246
Group title
SRG-APP-000516-UEM-100011
Rule ID
SV-284246r1223987_rule
Check ID
C-88810r1211877_chk
Fix ID
F-88715r1211878_fix