STIGQter STIGQter: STIG Summary: Samsung Android 16 COBO Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 13 May 2026:

Samsung Android 16 must disable the ability of the user to wipe the device.

DISA Rule

SV-276541r1183721_rule

Vulnerability Number

V-276541

Group Title

PP-MDF-993300

Rule Version

KNOX-16-011000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Samsung Android 16 device to disable the ability of the user from wiping the Android device. In addition, enable the admin to inject a recovery account on the device so they can unlock FRP.

On the MDM console, do the following:

COBO procedures – disallow factory reset:
1. Open user restrictions.
2. Enable "Disallow Factory Reset".

COBO procedures – set factory reset protection policy:
1. Select Device owner management >> Set factory reset protection.
2. From the "Accounts" section, go to Add Account >> Enter recovery account, then press "Ok".
3. From the "Enabled" section, select "Enabled" to enable factory reset protection policy.
4. Press "Save" to confirm all changes.

API: addUserRestriction, DISALLOW_FACTORY_RESET and setFactoryResetProtectionPolicy

Check Contents

Review configuration settings to confirm the user is unable to perform a factory reset and the admin has the ability to inject a recovery account on the device to unlock Factory Reset Protection (FRP).

This check procedure is performed on the device management tool and the Samsung Android 16 device.

On the MDM console:

Verify factory reset configuration.
COBO procedures:
1. Open user restrictions.
2. Verify "Disallow Factory Reset" is enabled.

Verify factory reset protection policy configuration.
1. From the Android Enterprise policy management, go to the Factory Reset Protection section.
2. Verify "Factory Reset Protection" is set to "Allow/Enabled".
3. Verify the correct Google Account ID(s) is/are listed as allowed to unlock the FRP.

On the managed Samsung Android 16 device, verify factory reset configuration.

COBO:
1. Open Settings >> General management >> Reset.
2. Tap the "Factory data reset" option.
3. Verify the "Action not allowed" pop up appears and that the factory data reset does not proceed.

If the Android device user is able to perform a factory reset or the admin cannot unlock the Android phone after an FRP event, this is a finding.

Vulnerability Number

V-276541

Documentable

False

Rule Version

KNOX-16-011000

Severity Override Guidance

Review configuration settings to confirm the user is unable to perform a factory reset and the admin has the ability to inject a recovery account on the device to unlock Factory Reset Protection (FRP).

This check procedure is performed on the device management tool and the Samsung Android 16 device.

On the MDM console:

Verify factory reset configuration.
COBO procedures:
1. Open user restrictions.
2. Verify "Disallow Factory Reset" is enabled.

Verify factory reset protection policy configuration.
1. From the Android Enterprise policy management, go to the Factory Reset Protection section.
2. Verify "Factory Reset Protection" is set to "Allow/Enabled".
3. Verify the correct Google Account ID(s) is/are listed as allowed to unlock the FRP.

On the managed Samsung Android 16 device, verify factory reset configuration.

COBO:
1. Open Settings >> General management >> Reset.
2. Tap the "Factory data reset" option.
3. Verify the "Action not allowed" pop up appears and that the factory data reset does not proceed.

If the Android device user is able to perform a factory reset or the admin cannot unlock the Android phone after an FRP event, this is a finding.

Check Content Reference

M

Target Key

5714