STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 2 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to Samsung Android OS 17 with Knox 3.x COPE Security Technical Implementation Guide

V-286470

CAT II (Medium)

The Samsung Android 17 device must be configured to disable web-based artificial intelligence (AI) interactions.

Rule ID

SV-286470r1256825_rule

STIG

Samsung Android OS 17 with Knox 3.x COPE Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000366

Discussion

Sensitive DoW data could be exposed when an AI app processes device data in the cloud. SFR ID: FMT_SMF.1.1 #47

Check Content

Verify the Samsung Android 17 device has been configured to disable web-based AI interactions.

On the Android 17 phone, try to browse to unauthorized AI URLs. Examples of input include chatgpt.com, claude.ai, gemini.google.com, and v0.dev.

Verify the unauthorized AI websites cannot be reached.

If the Samsung Android 17 device has not been configured to disable web-based AI interactions, this is a finding.

Fix Text

Configure the Samsung Android 17 device to disable web-based AI interactions.

For web-based AI in the browser: 

Create an App Configuration Policy: (Requires EMM Admin access)
1. Navigate to your EMM's Policy/App Configuration section and create a new policy targeted at Managed Devices/Android Enterprise. Select the Browser (Google Chrome) as the targeted application.

Configure the URL Blocklist:
Locate the URLBlocklist setting. Add the domains of the AI tools to be blocked. Examples of input include chatgpt.com, claude.ai, gemini.google.com, and v0.dev.

Block Incognito Mode:
1. In the same Chrome configuration layout, look for IncognitoModeAvailability. 
2. Set Incognito Mode to disabled. This ensures that users cannot bypass the URL block list by launching an anonymous browsing session.

Assign and Push:
Save the configuration and assign it to the device groups containing the user's COBO and COPE profiles.

Configuration for other browsers depends on the deployment type. 

COBO: Because the first step limits the managed Google Play store to only approved apps, ensure no other browsers (like Firefox, Opera, or Edge) are approved in the app allow list.
COPE: Create a Device Restrictions Policy for the Personal Profile and set "Disallow install of applications from unknown sources" to "True".