STIGUI
V-284349CAT II — Medium severitySV-284349r1224092_rule

The Omnissa WS1 UEM server must enforce a minimum 15-character password length.

Rule version OMW1-00-011400 · STIG v1 · 2026-08-31

Discussion

The shorter the password, the lower the number of possible combinations that need to be tested before the password is compromised.

Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password. The shorter the password, the lower the number of possible combinations that need to be tested before the password is compromised.

Use of more characters in a password helps to exponentially increase the time and/or resources required to compromise the password.

Satisfies: FMT_SMF.1(2)b Reference: PP-MDM-431018

Check

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords.

If "Minimum Password Length" is not set to "15", this is a finding.

Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.

Fix

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords.

Configure "Minimum Password Length" to "15".

Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.

Identifiers

Group ID
V-284349
Group title
SRG-APP-000164-UEM-000094
Rule ID
SV-284349r1224092_rule
Check ID
C-88913r1211914_chk
Fix ID
F-88818r1211915_fix