HONW-13-009000 - Honeywell Android 13 must be configured to disable multiuser modes.

Information

Multiuser mode allows multiple users to share a mobile device by providing a degree of separation between user data. To date, no mobile device with multiuser mode features meets DOD requirements for access control, data separation, and nonrepudiation for user accounts. In addition, the MDFPP does not include design requirements for multiuser account services. Disabling multiuser mode mitigates the risk of not meeting DOD multiuser account security policies.

SFR ID: FMT_SMF_EXT.1.1 #47a

Solution

Configure the Honeywell Android 13 device to disable multiuser modes.

On the EMM console:

COBO, COPE, and BYOAD:

1. Open 'User restrictions'.
2. Open 'Set user restrictions'.
3. Toggle 'Disallow modify accounts' to 'ON'.

Note: This only applies to the work profile for BYOAD. A user can modify accounts in the personal profile.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_HW_Android_13_Y25M04_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2a., CAT|II, CCI|CCI-002110, Rule-ID|SV-274405r1100857_rule, STIG-ID|HONW-13-009000, Vuln-ID|V-274405

Plugin: MDM

Control ID: ccec3b2341764b3e1386ef3bde545a73e7f0d49dac2d5a0d73d9c102bd539195