STIGQter STIGQter: STIG Summary: Apple visionOS 2 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 13 May 2026:

Apple visionOS 2 must allow the administrator (MDM) to perform the following management function: enable/disable VPN protection across the device and [selection: on a per-app basis, on a per-group of applications processes basis].

DISA Rule

SV-276374r1146618_rule

Vulnerability Number

V-276374

Group Title

PP-MDF-331090

Rule Version

AVOS-02-001000

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

If a third-party unmanaged VPN app is installed on the visionOS 2 device, do not configure the VPN app with a DOD network VPN profile.

Check Contents

Review the list of unmanaged apps installed on the Vision Pro and determine if any unmanaged third-party VPN clients are installed. If so, verify the VPN app is not configured with a DOD network (work) VPN profile.

This validation procedure is performed on the visionOS device only.

On the Vision Pro:
1. Open the Settings app.
2. Tap "General".
3. Tap the "VPN and Device Management" line and determine if any "Personal VPN" exists.
4. If not, the requirement has been met.
5. If there are personal VPNs, open each VPN app. Review the list of VPN profiles configured on the VPN client.
6. Verify no DOD network VPN profiles are configured on the VPN client.

If any third-party unmanaged VPN apps are installed (personal VPN) and they have a DOD network VPN profile configured on the client, this is a finding.

Note: This setting cannot be managed by the MDM administrator and is a User-Based Enforcement (UBE) requirement.

Vulnerability Number

V-276374

Documentable

False

Rule Version

AVOS-02-001000

Severity Override Guidance

Review the list of unmanaged apps installed on the Vision Pro and determine if any unmanaged third-party VPN clients are installed. If so, verify the VPN app is not configured with a DOD network (work) VPN profile.

This validation procedure is performed on the visionOS device only.

On the Vision Pro:
1. Open the Settings app.
2. Tap "General".
3. Tap the "VPN and Device Management" line and determine if any "Personal VPN" exists.
4. If not, the requirement has been met.
5. If there are personal VPNs, open each VPN app. Review the list of VPN profiles configured on the VPN client.
6. Verify no DOD network VPN profiles are configured on the VPN client.

If any third-party unmanaged VPN apps are installed (personal VPN) and they have a DOD network VPN profile configured on the client, this is a finding.

Note: This setting cannot be managed by the MDM administrator and is a User-Based Enforcement (UBE) requirement.

Check Content Reference

M

Target Key

5713