STIGQter STIGQter: STIG Summary: Apple visionOS 2 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 13 May 2026:

The Apple visionOS 2 must be supervised by the MDM.

DISA Rule

SV-276407r1146717_rule

Vulnerability Number

V-276407

Group Title

PP-MDF-993300

Rule Version

AVOS-02-013200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Use one of the following methods to supervise visionOS devices managed by the DOD mobile service provider.

Method 1:
- Register all current and new visionOS devices in the DOD mobile service provider's Automated Device Management/Apple Business Manager (ABM) account.
- Enable supervision of managed visionOS devices in the MDM.

Method 2:
- Configure each visionOS device using the Apple Configurator tool for Supervision.
- This method is usually only appropriate when MDM management of the DOD Apple device is not appropriate or an older device cannot be registered in ABM.

Check Contents

Review configuration settings to confirm site-managed visionOS devices are supervised.

This check procedure is performed on both the Apple visionOS management tool and the Vision Pro.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the visionOS management tool, verify all managed Apple devices are supervised (verification procedure will vary by MDM product).

Note: If the Apple device is not managed by an MDM and supervision is set up via Apple Configurator, this procedure is not applicable.

On the Vision Pro:
1. Open the Settings app.
2. Verify a message similar to the following appears on the screen: "This AVP is supervised by (name of site DOD mobile service provider)."

If site-managed visionOS devices are not supervised, this is a finding.

Vulnerability Number

V-276407

Documentable

False

Rule Version

AVOS-02-013200

Severity Override Guidance

Review configuration settings to confirm site-managed visionOS devices are supervised.

This check procedure is performed on both the Apple visionOS management tool and the Vision Pro.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the visionOS management tool, verify all managed Apple devices are supervised (verification procedure will vary by MDM product).

Note: If the Apple device is not managed by an MDM and supervision is set up via Apple Configurator, this procedure is not applicable.

On the Vision Pro:
1. Open the Settings app.
2. Verify a message similar to the following appears on the screen: "This AVP is supervised by (name of site DOD mobile service provider)."

If site-managed visionOS devices are not supervised, this is a finding.

Check Content Reference

M

Target Key

5713