2.5.6 Ensure Limit Ad Tracking Is Enabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Apple provides a framework that allows advertisers to target Apple users and end-users with advertisements. While many people prefer to see advertising that is relevant to them and their interests, the detailed information that is collected, correlated, and available to advertisers in repositories via data mining is often disconcerting. This information is valuable to both advertisers and attackers, and has been used with other metadata to reveal users' identities.

Organizations should manage advertising settings on computers rather than allow users to configure the settings.

Apple Information

Ad tracking should be limited on 10.15 and prior.

Rationale:

Organizations should manage user privacy settings on managed devices to align with organizational policies and user data protection requirements.

Impact:

Uses will see generic advertising rather than targeted advertising. Apple warns that this will reduce the number of relevant ads.

Solution

Perform the following to set limited ad tracking:
Graphical Method:

Open System Preferences

Select Security & Privacy

Select Privacy

Select Apple Advertising

Uncheck Personalized Ads

Terminal Method:
For each needed user, run the following command to enable limited ad tracking:

$ sudo -u <username> defaults write /Users/<username>/Library/Preferences/com.apple.Adlib.plist allowApplePersonalizedAdvertising -bool false

example:

$ sudo -u seconduser defaults write /Users/seconduser/Library/Preferences/com.apple.Adlib.plist forceLimitAdTracking -bool true

Profile Method:

Create or edit a configuration profile with the PayloadType of com.apple.AdLib

Add the key allowApplePersonalizedAdvertising

Set the key to <false/>

See Also

https://workbench.cisecurity.org/files/4002