STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Samsung Android OS 15 with Knox 3.x COBO Security Technical Implementation Guide

V-277011

CAT II (Medium)

Samsung Android 15 must disable the ability of the user to wipe the device.

Rule ID

SV-277011r1183586_rule

STIG

Samsung Android OS 15 with Knox 3.x COBO Security Technical Implementation Guide

Version

V1R3

CCIs

CCI-000366

Discussion

This feature must be disabled to comply with DOD electronic records retention requirements for mobile devices. Otherwise, mobile device users could wipe the device, which would violate DOD policy. SFR ID: FMT_MOF_EXT.1.2 #47

Check Content

Review configuration settings to confirm that the user is unable to perform a factory reset and the admin has the ability to inject a recovery account on the device to unlock Factory Reset Protection (FRP).

This check procedure is performed on the device management tool and the Samsung Android 15 device.

On the MDM console:

Verify factory reset configuration:

COBO:

1. Open user restrictions.
2. Verify "Disallow Factory Reset" is enabled.

Verify factory reset protection policy configuration: 

1. From the Android Enterprise policy management, go to the Factory Reset Protection section.
2. Verify "Factory Reset Protection" is set to "Allow/Enabled".
3. Verify the correct Google Account ID(s) is/are listed as allowed to unlock the FRP.

On the managed Samsung Android 15 device, verify factory reset configuration.

COBO:

1. Open Settings >> General management >> Reset.
2. Tap the "Factory data reset" option.
3. Verify the "Action not allowed" pop-up appears and the factory data reset does not proceed.

If the Android device user is able to perform a factory reset or the admin cannot unlock the Android phone after an FRP event, this is a finding.

Fix Text

Configure the Samsung Android 15 device to disable the ability of the user to wipe the Android device. Enable the admin to inject a recovery account on the device to unlock FRP.

On the MDM console:

Disallow factory reset:

COBO: 

1. Open user restrictions.
2. Enable "Disallow Factory Reset".

Set factory reset protection policy:

COBO: 

1. Select Device owner management >> Set factory reset protection.
2. From the "Accounts" section, go to Add Account >> Enter recovery account and press "Ok".
3. From the "Enabled" section, select "Enabled" to enable factory reset protection policy.
4. Press "Save" to confirm all changes.

API: addUserRestriction, DISALLOW_FACTORY_RESET and setFactoryResetProtectionPolicy