STIGQter STIGQter: STIG Summary: Apple visionOS 2 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 13 May 2026:

Apple visionOS 2 must be configured to enforce a passcode reuse prohibition of at least two generations.

DISA Rule

SV-276384r1146648_rule

Vulnerability Number

V-276384

Group Title

PP-MDF-993300

Rule Version

AVOS-02-006950

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Install a configuration profile to enforce a passcode reuse prohibition of at least two generations (passcode history).

Check Contents

Review configuration settings to confirm the Apple visionOS device has a passcode reuse prohibition of at least two generations.

This procedure is performed in the Apple visionOS management tool and on the Vision Pro.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Management tool, verify the "Passcode History" value is set to two or greater.

On the Vision Pro:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the configuration profile from the Apple visionOS management tool containing the password policy.
5. Tap "Restrictions".
6. Tap "Passcode".
7. Verify "Number of unique recent passcodes required" is listed as "two" or greater.

If the Apple visionOS device does not enforce a passcode reuse prohibition of at least two generations, this is a finding.

Vulnerability Number

V-276384

Documentable

False

Rule Version

AVOS-02-006950

Severity Override Guidance

Review configuration settings to confirm the Apple visionOS device has a passcode reuse prohibition of at least two generations.

This procedure is performed in the Apple visionOS management tool and on the Vision Pro.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Management tool, verify the "Passcode History" value is set to two or greater.

On the Vision Pro:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the configuration profile from the Apple visionOS management tool containing the password policy.
5. Tap "Restrictions".
6. Tap "Passcode".
7. Verify "Number of unique recent passcodes required" is listed as "two" or greater.

If the Apple visionOS device does not enforce a passcode reuse prohibition of at least two generations, this is a finding.

Check Content Reference

M

Target Key

5713