MSFT-11-008800 - Microsoft Android 11 must be configured to enforce that Wi-Fi Sharing is disabled.

Information

Wi-Fi Sharing is an optional configuration of Wi-Fi Tethering/Mobile Hotspot, which allows the device to share its Wi-Fi connection with other wirelessly connected devices instead of its mobile (cellular) connection.

Wi-Fi Sharing grants the 'other' device access to a corporate Wi-Fi network and may possibly bypass the network access control mechanisms. This risk can be partially mitigated by requiring the use of a preshared key for personal hotspots.

SFR ID: FMT_SMF_EXT.1.1 #47

Solution

Configure Microsoft Android 11 device to disable Wi-Fi Sharing.

Mobile Hotspot must be enabled in order to enable Wi-Fi Sharing. If the AO has not approved Mobile Hotspot, and it has been disabled on the EMM console, no further action is needed. If Mobile Hotspot is being used, use the following procedure to disable Wi-Fi Sharing:

On the EMM console:
1. Open 'Set user restrictions on parent'.
2. Toggle 'Disallow config tethering' to 'On'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Android_11_FY24M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-255190r959010_rule, STIG-ID|MSFT-11-008800, Vuln-ID|V-255190

Plugin: MDM

Control ID: f2ad47838918429d871d667eddedbb9f167f098ee9881d33837a6f54e752044e