MSFT-11-002800 - Microsoft Android 11 must be configured to disable developer modes.

Information

Developer modes expose features of the Microsoft Android device that are not available during standard operation. An adversary may leverage a vulnerability inherent in a developer mode to compromise the confidentiality, integrity, and availability of DOD sensitive information. Disabling developer modes mitigates this risk.

SFR ID: FMT_SMF_EXT.1.1 #26

Solution

Configure the Microsoft Android 11 device to disable developer modes.

On the EMM console:
1. Open 'Set user restrictions' section.
2. Toggle 'Disallow debugging features' to 'On'.
3. Open 'Set user restrictions on parent' section.
4. Toggle 'Disallow debugging features' to 'On'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Android_11_FY24M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-255213r958478_rule, STIG-ID|MSFT-11-002800, Vuln-ID|V-255213

Plugin: MDM

Control ID: 314c399b4801bb5ed920830a6b999801994e892ecf5a84ed4f362f8b587ddd45