MSFT-11-003500 - Microsoft Android 11 must be configured to disable USB mass storage mode.

Information

USB mass storage mode enables the transfer of data and software from one device to another. This software can include malware. When USB mass storage is enabled on a mobile device, it becomes a potential vector for malware and unauthorized data exfiltration. Prohibiting USB mass storage mode mitigates this risk.

SFR ID: FMT_SMF_EXT.1.1 #39a

Solution

Configure the Microsoft Android 11 device to disable USB mass storage mode.

On the EMM console:
1. Open 'User restrictions on parent'.
2. Toggle 'Disallow usb file transfer'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Android_11_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-41, CAT|II, CCI|CCI-002546, Rule-ID|SV-255215r870828_rule, STIG-ID|MSFT-11-003500, Vuln-ID|V-255215

Plugin: MDM

Control ID: f77d5fc42f22dd4745305779d6c4df68d28280167ba9538de4de643c8ea5935e