1.25 Ensure 'Guest profiles' do not exist

Information

Do not add any guest profiles on the device.
The recommended state for this setting is: Remove Guest profiles.

Rationale:

Users and the guest profile can do most of the same things as the device's owner, but each profile has its own storage space. Guests could install malicious apps or carry out any other malicious activities that may compromise overall device security. Also, Wi-Fi and Bluetooth connections are shared which could give guests unauthorized access to networks/devices that could compromise data. Hence, do not add any guest profiles on the device.
If you need to give your device to someone for temporary use, use Screen Pinning to restrict access to the desired app and be in the complete visibility of your device all the time.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps remove the Guest profile:

Open Quick Settings drawer.
Tap the Profile icon.
Switch to Guest profile.
Open Quick Settings drawer.
Tap Remove guest.
Confirm removal by tapping remove.

Impact:

None

Default Value:

By default, Guest profiles do not exist.

See Also

https://workbench.cisecurity.org/files/2466