AIOS-13-013700 - The Apple iOS/iPadOS must be Supervised by the MDM.


When an iOS/iPadOS is not supervised, the DoD mobile service provider cannot control when new iOS/iPadOS updates are installed on site managed devices. Most updates should be installed immediately to mitigate new security vulnerabilities, while some sites need to test each update prior to installation to insure critical missions are not adversely impacted by the update.

Also, several password and data protection controls can only be implemented when an Apple device is Supervised.


NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.


Use one of the following methods to Supervise iOS and iPadOS devices managed by the DoD mobile service provider.

Method 1:
-Register all current and new iOS and iPadOS devices in the DoD mobile service provider's Device Enrollment Program (DEP)/Apple Business Manager (ABM) account.
-Enable Supervision of managed iOS/iPadOS devices in the MDM.

Method 2:
-Configure each iOS/iPadOS device using the Apple Configurator tool for Supervision. This method is usually only appropriate when MDM management of the DoD Apple device is not appropriate or an older device cannot be registered in DEP/ABM.

See Also

Item Details

References: CAT|II, CCI|CCI-000097, CCI|CCI-000366, CCI|CCI-000370, Rule-ID|SV-106621r1_rule, STIG-ID|AIOS-13-013700, Vuln-ID|V-97517

Plugin: MDM

Control ID: 555fed3018f1bb30d1227b0e02bd56492de78ab7e78215ae2aad677b94f0d7bf