2.1.1 - AirWatch - Set Security to disallow profile removal

Information

The device can be configured to always allow the removal of a profile, to allow the removal of a profile only with a profile-specific password, or to never allow the removal of a profile, on a per-profile basis. By default, the iPCU configuration allows the profile to be removed by the user. To ensure profile settings remain in effect, profile removal must be disallowed.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the AirWatch console, open the iOS device profile. Under General verify that Allow Removal is set to either Never or With Authorization.
NOTE: This option will not appear if Allow use of Safari is not enabled.

See Also

https://workbench.cisecurity.org/files/1678

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-19

Plugin: MDM

Control ID: e150ef19a3f658e3eaf291fb37a179fa604c9011d15dc29a8a8c040d2bb3e69b