2.2.1.3 Ensure 'Allow managed apps to store data in iCloud' is set to 'Disabled'

Information

This recommendation pertains to managed apps storing and syncing data through iCloud.

Rationale:

This recommendation addresses data leakage. It prevents a user from installing an app that is managed by the organization on a personal device and having iCloud sync the managed app data to the personal, non-managed app.

Impact:

Syncing managed app data between multiple managed devices will not be possible.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left windowpane, click on the Restrictions tab.

In the right windowpane, under the tab Functionality, uncheck the checkbox for Allow managed apps to store data in iCloud.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/files/3064