1.26 Ensure 'Add users when device is locked' is set to Disabled

Information

Do not allow adding users on a locked device.

Rationale:

Users and the guest profile can do most of the same things as the device's owner, but each profile has its own storage space. Guests could install malicious apps or carry out any other malicious activities that may compromise overall device security. Also, Wi-Fi and Bluetooth connections are shared which could give guests unauthorized access to networks/devices that could compromise data. Hence, Add users when device is locked setting should be disabled.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Add users when device is locked setting:

* Tap System Settings Gear Icon.
* Scroll to Device section.
* Tap Users.
* Toggle Add users when device is locked setting to Off position.

Impact:

Users will not be able to add additional users when the device is locked.

See Also

https://workbench.cisecurity.org/files/1477

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: MDM

Control ID: 401664d84fff9467f92f21585b2b37828c0f07e25d9ff69e925e383b6cd54fd1