SV-260152r1117274_rule
V-260152
PP-MDF-333280
GOOG-14-708900
CAT II
10
Configure the Google Android 14 device to enable the access control policy that prevents [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].
Note: All application data is inherently sandboxed and isolated from other applications. To disable copy/paste on the EMM Console:
1. Open "User restrictions".
2. Open "Set user restrictions".
3. Toggle "Disallow cross profile copy/paste" to "ON".
4. Toggle "Disallow sharing data into the profile" to "ON".
Review documentation on the managed Google Android 14 device and inspect the configuration on the Google Android device to verify the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.
This validation procedure is performed only on the EMM Administration Console.
On the EMM console:
1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow cross profile copy/paste" is toggled to "ON".
4. Verify that "Disallow sharing data into the profile" is toggled to "ON".
If the EMM console device policy is not set to disable data sharing between profiles, this is a finding.
V-260152
False
GOOG-14-708900
Review documentation on the managed Google Android 14 device and inspect the configuration on the Google Android device to verify the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.
This validation procedure is performed only on the EMM Administration Console.
On the EMM console:
1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow cross profile copy/paste" is toggled to "ON".
4. Verify that "Disallow sharing data into the profile" is toggled to "ON".
If the EMM console device policy is not set to disable data sharing between profiles, this is a finding.
M
5589