STIGQter STIGQter: STIG Summary: Apple visionOS 2 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 13 May 2026:

Apple visionOS 2 must implement the management setting: not allow use of Handoff.

DISA Rule

SV-276394r1146678_rule

Vulnerability Number

V-276394

Group Title

PP-MDF-993300

Rule Version

AVOS-02-010800

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Install a configuration profile to disable continuation of activities among devices and workstations. This is a supervised-only control.

Check Contents

This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding.

If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Allow Handoff" is disabled.

This check procedure is performed on both the Apple visionOS management tool and the Vision Pro.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple visionOS management tool, verify "Allow Handoff" is unchecked.

Alternatively, verify the text "<key>allowActivityContinuation</key> <false/>" appears in the configuration profile (.mobileconfig file).

On the Vision Pro:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the configuration profile from the Apple visionOS management tool containing the restrictions policy.
5. Tap "Restrictions".
6. Verify "Handoff not allowed" is listed.

If "Allow Handoff" is checked in the Apple visionOS management tool, "<key>allowActivityContinuation</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Handoff not allowed", this is a finding.

Vulnerability Number

V-276394

Documentable

False

Rule Version

AVOS-02-010800

Severity Override Guidance

This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding.

If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Allow Handoff" is disabled.

This check procedure is performed on both the Apple visionOS management tool and the Vision Pro.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple visionOS management tool, verify "Allow Handoff" is unchecked.

Alternatively, verify the text "<key>allowActivityContinuation</key> <false/>" appears in the configuration profile (.mobileconfig file).

On the Vision Pro:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the configuration profile from the Apple visionOS management tool containing the restrictions policy.
5. Tap "Restrictions".
6. Verify "Handoff not allowed" is listed.

If "Allow Handoff" is checked in the Apple visionOS management tool, "<key>allowActivityContinuation</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Handoff not allowed", this is a finding.

Check Content Reference

M

Target Key

5713