1.24 Ensure 'Add users from lock screen' is set to Disabled

Information

Do not allow adding users on a locked device.

Rationale:

Users and the guest profile can do most of the same things as the device's owner, but each
profile has its own storage space. Guests could install malicious apps or carry out any other
malicious activities that may compromise overall device security. Also, Wi-Fi and Bluetooth
connections are shared which could give guests unauthorized access to networks/devices
that could compromise data. Hence, Add users from lock screen setting should be
disabled.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Add users from lock screen setting:

1. Tap Settings Gear Icon.
2. Tap Users & accounts.
3. Toggle Add users from lock screen setting to Off position.


Impact:

Users will not be able to add additional users when the device is locked.

Default Value:

By default, Add users from lock screen setting is enabled.

See Also

https://workbench.cisecurity.org/files/2076