3.2.1.24 Ensure 'Allow Handoff' is set to 'Disabled'

Information

This recommendation pertains to Apple's Handoff data-sharing mechanism.

Rationale:

Handoff does not enforce managed application boundaries. This allows managed application data to be moved to the unmanaged application space on another device, which may result in data leakage.

Impact:

End users may be inconvenienced by disabling Handoff on their personal devices.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Allow Handoff.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548