STIGQter STIGQter: STIG Summary:

Google Android 14 MDFPP 3.3 BYOAD Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 01 Oct 2025

CheckedNameTitle
SV-260082r1120908_ruleGoogle Android 14 must prohibit DOD VPN profiles in the Personal Profile.
SV-260126r985624_ruleGoogle Android 14 must be configured to enforce a minimum password length of six characters and not allow passwords that include more than four repeating or sequential characters.
SV-260128r971318_ruleGoogle Android 14 must be configured to lock the display after 15 minutes (or less) of inactivity.
SV-260129r958388_ruleGoogle Android 14 must be configured to not allow more than 10 consecutive failed authentication attempts.
SV-260130r959010_ruleGoogle Android 14 must be configured to enforce an application installation policy by specifying one or more authorized application repositories.
SV-260131r958804_ruleGoogle Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].
SV-260132r1032950_ruleGoogle Android 14 allowlist must be configured to not include applications with the following characteristics (work profile only): 1. Back up mobile device (MD) data to non-DOD cloud servers (including user and application access to cloud backup services); 2. Transmit MD diagnostic data to non-DOD servers; 3. Voice assistant application if available when MD is locked; 4. Voice dialing application if available when MD is locked; 5. Allows synchronization of data or applications between devices associated with user; and 6. Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers. 7. Apps which backup their own data to a remote system.
SV-260133r958404_ruleGoogle Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
SV-260137r985628_ruleGoogle Android 14 must be configured to disable trust agents.
SV-260142r958390_ruleGoogle Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the Work Profile.
SV-260149r1117267_ruleGoogle Android 14 must be configured to not allow backup of all work profile applications to remote systems.
SV-260152r1117274_ruleGoogle Android 14 must be configured to disable exceptions to the access control policy that prevent [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].
SV-260160r959010_ruleGoogle Android 14 users must complete required training.
SV-260162r959010_ruleGoogle Android 14 must have the DOD root and intermediate PKI certificates installed (work profile only).
SV-260163r959010_ruleThe Google Android 14 work profile must be configured to prevent users from adding personal email accounts to the work email app.
SV-260164r959010_ruleThe Google Android 14 work profile must be configured to enforce the system application disable list (work profile only).
SV-260165r959010_ruleGoogle Android 14 must be provisioned as a BYOAD device (Android work profile for employee-owned devices [BYOD]).
SV-260166r959010_ruleThe Google Android 14 work profile must be configured to disable automatic completion of workspace internet browser text input.
SV-260167r959010_ruleThe Google Android 14 work profile must be configured to disable the autofill services.
SV-260170r959010_ruleAndroid 14 devices must have the latest available Google Android 14 operating system installed.
SV-260171r959010_ruleAndroid 14 devices must be configured to disable the use of third-party keyboards (work profile only).
SV-260174r959010_ruleThe Google Android 14 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates (work profile).
SV-276972r1134351_ruleGoogle Android 14 BYOAD devices must have a Mobile Threat Detection (MTD) app installed.