Nutanix AOS must authenticate users individually prior to using a group authenticator.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-279438 | NXAC-AS-000032 | SV-279438r1191100_rule | CCI-004045 | medium |
| Description | ||||
| To ensure individual accountability and prevent unauthorized access, application server users (and any processes acting on behalf of application server users) must be individually identified and authenticated. A group authenticator is a generic account used by multiple individuals. Use of a group authenticator alone does not uniquely identify individual users. Application servers must ensure individual users are authenticated prior to authenticating via role or group authentication. This is to ensure there is nonrepudiation for actions taken. | ||||
| STIG | Date | |||
| Nutanix Acropolis Application Server Security Technical Implementation Guide | 2026-02-24 | |||
Details
Check Text (C-279438r1191100_chk)
Confirm the Nutanix VM application server is set to use enterprise user management systems. Envoy Reverse Proxy does not support group authenticators.
1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
If an Active Directory or OpenLDAP servers are not configured, this is a finding.
Fix Text (F-83896r1191099_fix)
Configure the Nutanix VM application server to use an enterprise user management system to authenticate individual users.
1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
4. Add an Active Directory or OpenLDAP server to the directory list.
Alternatively, individual local users can be created within Prism.
1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Local User Management.
4. Select "+ New Users".