STIGQter STIGQter: STIG Summary: Honeywell Android 13 COBO Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Apr 2025:

Honeywell Android 13 must be configured to disable multiuser modes.

DISA Rule

SV-274309r1100447_rule

Vulnerability Number

V-274309

Group Title

PP-MDF-333290

Rule Version

HONW-13-009000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Honeywell Android 13 device to disable multiuser modes.

On the EMM console:

COBO, COPE, and BYOAD:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Toggle "Disallow modify accounts" to ON.

Note: This only applies to the work profile for BYOAD. A user can modify accounts in the personal profile.

Check Contents

Review documentation on the managed Honeywell Android 13 device and inspect the configuration on the Honeywell Android device to disable multiuser modes.

This validation procedure is performed on both the EMM Administration Console and the managed Honeywell Android 13 device.

On the EMM console:

COBO, COPE, and BYOAD:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow modify accounts" is toggled to "ON".

Note: This applies only to the work profile for BYOAD. A user can modify accounts in the personal profile.

On the managed Honeywell Android 13 device:

COBO and COPE:

1. Go to Settings >> Passwords & accounts >> Accounts for Owner.
2. Tap "Add account".
3. Verify that the action is not allowed.

BYOAD:

1. Go to Settings >> Passwords & accounts >> Work.
2. Tap "Add account".
3. Verify that the action is not allowed.

If the EMM console device policy is not set to disable multiuser modes or on the managed Honeywell Android 13 device, the device policy is not set to disable multiuser modes, this is a finding.

Vulnerability Number

V-274309

Documentable

False

Rule Version

HONW-13-009000

Severity Override Guidance

Review documentation on the managed Honeywell Android 13 device and inspect the configuration on the Honeywell Android device to disable multiuser modes.

This validation procedure is performed on both the EMM Administration Console and the managed Honeywell Android 13 device.

On the EMM console:

COBO, COPE, and BYOAD:

1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow modify accounts" is toggled to "ON".

Note: This applies only to the work profile for BYOAD. A user can modify accounts in the personal profile.

On the managed Honeywell Android 13 device:

COBO and COPE:

1. Go to Settings >> Passwords & accounts >> Accounts for Owner.
2. Tap "Add account".
3. Verify that the action is not allowed.

BYOAD:

1. Go to Settings >> Passwords & accounts >> Work.
2. Tap "Add account".
3. Verify that the action is not allowed.

If the EMM console device policy is not set to disable multiuser modes or on the managed Honeywell Android 13 device, the device policy is not set to disable multiuser modes, this is a finding.

Check Content Reference

M

Target Key

5701