STIGQter STIGQter: STIG Summary: Samsung Android 16 COBO Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 13 May 2026:

Samsung Android must be configured to not allow more than 10 consecutive failed authentication attempts.

DISA Rule

SV-276559r1139199_rule

Vulnerability Number

V-276559

Group Title

PP-MDF-333040

Rule Version

KNOX-16-005300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Samsung Android devices to allow only 10 or fewer consecutive failed authentication attempts.

On the management tool, in the device password policies, set "max password failures for local wipe" to "10" attempts or fewer.

A device password must be set for "max password failures for local wipe" to become active.

API: setMaximumFailedPasswordsForWipe

Check Contents

Review the configuration to determine if the Samsung Android devices are allowing only 10 or fewer consecutive failed authentication attempts.

This validation procedure is performed on both the management tool and the Samsung Android device.

On the management tool, in the device password policies, verify "max password failures for local wipe" is set to "10" attempts or less.

On the Samsung Android device:
1. Open Settings >> Lock screen and AOD.
2. Verify "Secure lock settings" is present and tap it.
3. Enter current password.
4. Verify "Auto factory reset" is grayed out, and cannot be configured.
Note: When "Auto factory reset" is grayed out, this indicates the Administrator (MDM) is in control of the setting to wipe the device after 10 or fewer consecutive failed authentication attempts.

If on the management tool "max password failures for local wipe" is not set to "10" attempts or less, or on the Samsung Android device the "Auto factory reset" menu can be configured, this is a finding.

Vulnerability Number

V-276559

Documentable

False

Rule Version

KNOX-16-005300

Severity Override Guidance

Review the configuration to determine if the Samsung Android devices are allowing only 10 or fewer consecutive failed authentication attempts.

This validation procedure is performed on both the management tool and the Samsung Android device.

On the management tool, in the device password policies, verify "max password failures for local wipe" is set to "10" attempts or less.

On the Samsung Android device:
1. Open Settings >> Lock screen and AOD.
2. Verify "Secure lock settings" is present and tap it.
3. Enter current password.
4. Verify "Auto factory reset" is grayed out, and cannot be configured.
Note: When "Auto factory reset" is grayed out, this indicates the Administrator (MDM) is in control of the setting to wipe the device after 10 or fewer consecutive failed authentication attempts.

If on the management tool "max password failures for local wipe" is not set to "10" attempts or less, or on the Samsung Android device the "Auto factory reset" menu can be configured, this is a finding.

Check Content Reference

M

Target Key

5714