GOOG-16-013000 - Google Android 16 must disable the user's ability to wipe the device.

Information

This feature must be disabled to comply with DOD electronic records retention requirements for mobile devices. Otherwise, mobile device users could wipe the device, which would violate DOD policy.

SFR ID: FMT_MOF_EXT.1.2 #47

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure Google Android 16 device to disable the ability of the user to wipe the Android device. Enable the admin to inject a recovery account on the device so they can unlock FRP.

On the MDM console:

Disallow factory reset:

COBO and COPE:

1. Open user restrictions.
2. Enable 'Disallow Factory Reset'.

Set factory reset protection policy:

COBO and COPE:

1. Device owner management >> Set factory reset protection.
2. From Accounts Section: Add Account >> Enter recovery account >> press 'Ok'.
3. From Enabled Section: Select 'Enabled' to enable FRP policy.
4. Press 'Save' to confirm all changes.

Configuration API: factoryResetDisabled, frpAdminEmails[ ]

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_16_Y25M08_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-276889r1140459_rule, STIG-ID|GOOG-16-013000, Vuln-ID|V-276889

Plugin: MDM

Control ID: 392bad7ff95811209b54e9692f6a46e0f1888621a719c3e2707b6d9caa28992d