STIGQter STIGQter: STIG Summary: Zebra Technologies Android 14 COPE Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 13 May 2026:

Zebra Android 14 must disable the user's ability to wipe the device.

DISA Rule

SV-283659r1190388_rule

Vulnerability Number

V-283659

Group Title

PP-MDF-993300

Rule Version

ZEBR-14-013000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Zebra Android 14 device to disable user's ability to wipe the Android device. Enable the admin to inject a recovery account on the device so they can unlock FRP.

On the MDM console:

Disallow factory reset:

COBO and COPE:

1. Open user restrictions.
2. Enable "Disallow Factory Reset".

Set factory reset protection policy:

COBO and COPE:

1. Device owner management >> Set factory reset protection.
2. From Accounts section: Add Account >> Enter recovery account >> Press "OK".
3. From Enabled section: Select "Enabled" to enable FRP policy.
4. Press "Save" to confirm all changes.

Configuration API: factoryResetDisabled, frpAdminEmails[ ]

Check Contents

Review configuration settings to confirm the user is unable to perform a factory reset and the admin has the ability to inject a recovery account on the device so they can unlock Factory Reset Protection (FRP).

This check procedure is performed on the device management tool and the Zebra Android 14 device.

On the MDM console:

Verify factory reset configuration:

COBO and COPE:

1. Open user restrictions.
2. Verify that "Disallow Factory Reset" is enabled.

Verify factory reset protection policy configuration:

From the Android Enterprise policy management:

1. Go to the Factory Reset Protection section.
2. Verify that "Factory Reset Protection" is set to "Allow/Enabled".
3. Verify that the correct Zebra Account ID(s) is/are listed as allowed to unlock the FRP.

On the managed Zebra Android 14 device, verify factory reset configuration:

COBO and COPE:

1. Open Settings >> General management >> Reset.
2. Tap the "Factory data reset" option.
3. Verify that the "Action not allowed" pop-up appears and factory data reset does not proceed.

If the Android device user is able to perform a factory reset or the admin cannot unlock the Android phone after an FRP event, this is a finding.

Vulnerability Number

V-283659

Documentable

False

Rule Version

ZEBR-14-013000

Severity Override Guidance

Review configuration settings to confirm the user is unable to perform a factory reset and the admin has the ability to inject a recovery account on the device so they can unlock Factory Reset Protection (FRP).

This check procedure is performed on the device management tool and the Zebra Android 14 device.

On the MDM console:

Verify factory reset configuration:

COBO and COPE:

1. Open user restrictions.
2. Verify that "Disallow Factory Reset" is enabled.

Verify factory reset protection policy configuration:

From the Android Enterprise policy management:

1. Go to the Factory Reset Protection section.
2. Verify that "Factory Reset Protection" is set to "Allow/Enabled".
3. Verify that the correct Zebra Account ID(s) is/are listed as allowed to unlock the FRP.

On the managed Zebra Android 14 device, verify factory reset configuration:

COBO and COPE:

1. Open Settings >> General management >> Reset.
2. Tap the "Factory data reset" option.
3. Verify that the "Action not allowed" pop-up appears and factory data reset does not proceed.

If the Android device user is able to perform a factory reset or the admin cannot unlock the Android phone after an FRP event, this is a finding.

Check Content Reference

M

Target Key

5732