Big Sur - Disable iCloud Desktop and Document Folder Sync

Information

The macOS system's ability to automatically synchronize a user's desktop and documents folder to their iCloud Drive _MUST_ be disabled.

Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated file synchronization _MUST_ be controlled by an organization approved service.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.applicationaccess:
allowCloudDesktopAndDocuments:
False

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-20, 800-53|AC-20(1), 800-53|CM-7, 800-53|CM-7(1), 800-53|SC-7(10), CCE|CCE-85292-1

Plugin: Unix

Control ID: 88fb82b6fbcbaa3ed00a596d049ffdaabb9d8c35be6df9fa92410542716b0eef