3.2.1.22 Ensure 'Allow Handoff' is set to 'Disabled'

Information

This recommendation pertains to Apple's Handoff data sharing mechanism.

Rationale:

Handoff does not enforce managed app boundaries. This allows managed app data to be moved to the unmanaged app space on another device, which may result in data leakage.

Impact:

End-users may be inconvenienced by disabling Handoff on their personal devices.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left windowpane, click on the Restrictions tab.

In the right windowpane, under the tab Functionality, uncheck the checkbox for Allow Handoff.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/files/3064