STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Apple visionOS 2 Security Technical Implementation Guide

V-276383

CAT II (Medium)

Apple visionOS 2 must be configured to not allow more than 10 consecutive failed authentication attempts.

Rule ID

SV-276383r1146645_rule

STIG

Apple visionOS 2 Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000044

Discussion

The more attempts an adversary has to guess a password, the more likely the adversary will enter the correct password and gain access to resources on the device. Setting a limit on the number of attempts mitigates this risk. Setting the limit at 10 or fewer gives authorized users the ability to make a few mistakes when entering the password but still provides adequate protection against dictionary or brute force attacks on the password. SFR ID: FMT_SMF.1.1 #2, FIA_AFL_EXT.1.5

Check Content

Review configuration settings to confirm that consecutive failed authentication attempts is set to 10 or fewer.

This procedure is performed in the Apple visionOS management tool and on the Vision Pro. 

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. 

In the Management tool, verify the "Maximum number of failed attempts" value is set to 10 or fewer.

Alternatively, verify the text "<key>maxFailedAttempts</key> <integer>10</integer>" appears in the configuration profile (.mobileconfig file). It also is acceptable for the integer value to be fewer than 10.

On the Vision Pro: 
1. Open the Settings app. 
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the configuration profile from the visionOS management tool containing the password policy.
5. Tap "Restrictions".
6. Tap "Passcode".
7. Verify "Max failed attempts" is listed as "10" or fewer.

If the "Maximum number of failed attempts" is more than 10 in the visionOS management tool, "<key>maxFailedAttempts</key> " has an integer value of more than 10, or the password policy on the Vision Pro does not list "Max failed attempts" of 10 or fewer, this is a finding.

Fix Text

Install a configuration profile to allow only 10 or fewer consecutive failed authentication attempts.