2.2.1.3 Ensure 'Allow managed apps to store data in iCloud' is set to 'Disabled'

Information

This recommendation pertains to managed applications storing and syncing data through iCloud.

Rationale:

This recommendation addresses data leakage. It prevents a user from installing an application that is managed by the organization on a personal device and allowing iCloud to sync the managed application's data to the personal, non-managed application.

Impact:

Syncing managed application data between multiple managed devices will not be possible.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Allow managed apps to store data in iCloud.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548