SV-276868r1140396_rule
V-276868
PP-MDF-333280
GOOG-16-008900
CAT II
10
Configure the Google Android 16 device to enable the access control policy that prevents [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].
Note: All application data is inherently sandboxed and isolated from other applications. To disable copy/paste on the EMM console:
COPE:
1. Open "User restrictions".
2. Open "Set user restrictions".
3. Toggle "Disallow cross profile copy/paste" to "ON".
Configuration API: DISALLOW_CROSS_PROFILE_COPY_PASTE
Review documentation on the managed Google Android 16 device and inspect the configuration on the Google Android device to verify that the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.
This validation procedure is performed only on the EMM Administration Console.
On the EMM console:
COPE:
1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow cross profile copy/paste" is toggled to "ON".
If the EMM console device policy is not set to disable data sharing between profiles, this is a finding.
V-276868
False
GOOG-16-008900
Review documentation on the managed Google Android 16 device and inspect the configuration on the Google Android device to verify that the access control policy that prevents [selection: application processes] from accessing [selection: all] data stored by other [selection: application processes] is enabled.
This validation procedure is performed only on the EMM Administration Console.
On the EMM console:
COPE:
1. Open "User restrictions".
2. Open "Set user restrictions".
3. Verify that "Disallow cross profile copy/paste" is toggled to "ON".
If the EMM console device policy is not set to disable data sharing between profiles, this is a finding.
M
5717