Information
This recommendation pertains to disabling MAC randomization as needed.
Rationale:
MAC randomization is a feature available from iOS 14 onward and is enabled by default. Although this feature enhances privacy for individuals by using random and different addresses for each Wi-Fi network, it can lead to problems in some circumstances, such as captive portals, MAC-based Access Control Lists, etc. In such cases, disabling this feature may be necessary. This is a per-network setting, meaning it can be turned off for specific networks only.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
This remediation procedure cannot be accomplished with a checkbox, it needs to be applied on a per-network basis as appropriate.
From the Configuration Profile:
Open Apple Configurator.
Open the Configuration Profile.
In the left window pane, click on the Wi-Fi tab.
In the right window pane, select the relevant Wi-Fi configuration.
In the right window pane, check the checkbox for Disable Association MAC Randomization.
Deploy the Configuration Profile.
From the device:
Tap Settings.
Tap Wi-Fi.
Tap the relevant network.
Disable the option Private Address.
Item Details
Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION
References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1
Control ID: 99c805a84f4884b5a4af2d9c9ecc771f00d97e8cbc3eb07bd56abfa50b8740e3