AIOS-26-016000 - Apple iOS/iPadOS 26 must disable the ability of the user to wipe the device.

Information

This feature must be disabled in order to comply with DOD electronic records retention requirements for mobile devices. Otherwise, mobile device users could wipe the device, which would violate DOD policy.

SFR ID: FMT_MOF_EXT.1.2 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a configuration profile to disable 'Allow Erase All Content and Settings'. This is a supervised-only control.

Configuration Profile Key: allowEraseCointentAndSettings

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_iOS-iPadOS_26_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-278832r1151199_rule, STIG-ID|AIOS-26-016000, Vuln-ID|V-278832

Plugin: MDM

Control ID: dec6de060bcba3cb6ba4fa44f846fbf5050ac5e537034776f4395c882203f089