STIGUI
V-284351CAT II — Medium severitySV-284351r1224094_rule

The Omnissa WS1 UEM server must enforce password complexity by requiring at least one uppercase character to be used.

Rule version OMW1-00-011600 · STIG v1 · 2026-08-31

Discussion

Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.

Password complexity is one factor of several that determine how long it takes to crack a password. The more complex the password is, the greater the number of possible combinations that need to be tested before the password is compromised.

Satisfies: FMT_SMF.1(2)b Reference: PP-MDM-431020

Satisfies: SRG-APP-000166-UEM-000096, SRG-APP-000167-UEM-000097, SRG-APP-000168-UEM-000098, SRG-APP-000169-UEM-000099

Check

Authenticate to the Workspace ONE UEM console as an administrator.

Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords.

If "Password complexity level" is not set to "Mixed case, alphabetic, numeric and special characters", this is a finding.

Note: If this procedure is not seen on the console, the Cloud Service Provider (CSP) is managing the setting. Contact the CSP to review the required setting.

Fix

Authenticate to the Workspace ONE UEM console as an administrator.

1. Navigate to Groups & Settings >> All Settings >> Admin >> Console Security >> Passwords. 2. Configure "Password complexity level" to "Mixed case, alphabetic, numeric and special characters". 3. Click "Save".

Note: If this procedure is not seen on the console, the CSP is managing the setting. Contact the CSP to implement the required setting.

Identifiers

Group ID
V-284351
Group title
SRG-APP-000166-UEM-000096
Rule ID
SV-284351r1224094_rule
Check ID
C-88915r1211920_chk
Fix ID
F-88820r1211966_fix