2.7.2 Audit iPhone Mirroring

Information

iPhone Mirroring is a new feature offered in iOS 18 and macOS 15.0 Sequoia. It allows a macOS device to remotely access an iOS device connected to the same Apple Account. If a user has different Apple Accounts signed into iOS and macOS (ex. a managed Apple Account on macOS and a personal Apple Account on iOS), the feature is not available.

Enabling iPhone Mirroring may allow a macOS device to capture data from an iOS device (ex Image Capture). This would occur where the macOS device has not been approved to access that information by your organization's policies and the iOS device has been approved (or vice-versa).

If iPhone Mirroring is currently in use on an iOS device, the lock screen will have a notification that states iPhone in Use and state what device is using it. If iPhone Mirroring was in use on an iOS device but is no longer in use, the first time the user unlocks the iOS device it will notify the user that iPhone was used from Mac

Solution

Perform the following to configure iPhone Mirroring:

Graphical Method:

- Open System Settings
- Select Desktop & Dock
- Under the Widgets sub-header, verify iPhone is configured to your organization's requirements

Note: The iPhone setting will only show up if there are multiple iPhones being connected to the user's Apple Account and setup with iPhone mirroring.

Profile Method:

Create or edit a configuration profile with the following information:

- The PayloadType string is com.apple.applicationaccess
- The key to include is allowiPhoneMirroring
- The key must be set to either <true/> or <false/> depending on your organization's requirements

Impact:

If iPhone Mirroring is disabled, it would stop a user from accessing information on their iOS device while using their macOS device.

See Also

https://workbench.cisecurity.org/benchmarks/18636

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: dcaab2276bbe479492ff84d5ba237e816816900e66cd05492c122c4bbd50cc83