Rule ID
SV-250943r853256_rule
Version
V1R4
CCIs
CCI-000366, CCI-002110
Multiuser mode allows multiple users to share a mobile device by providing a degree of separation between user data. To date, no mobile device with multiuser mode features meets DoD requirements for access control, data separation, and nonrepudiation for user accounts. In addition, the MDFPP does not include design requirements for multiuser account services. Disabling multiuser mode mitigates the risk of not meeting DoD multiuser account security policies. SFR ID: FMT_SMF_EXT.1.1 #47a
Verify multiuser mode is disabled in the MDM console for iPadOS devices. If multiuser mode is not disabled in the MDM console for iPadOS devices, this is a finding.
Disable multiuser mode in the MDM console for iPadOS devices.