SV-102945r1_rule
V-92857
PP-MDF-991000
KNOX-09-000010
CAT II
10
Configure Samsung Android to prevent users from adding personal email accounts to the work email app.
On the MDM console, for the device, do the following:
1. In the "Android account" group, configure "account management" to "disable for the work email app".
2. Provision the user's email account for the work email app.
Refer to the MDM documentation to determine how to provision users' work email accounts for the work email app.
Review device configuration settings to confirm that users are prevented from adding personal email accounts to the work email app.
This procedure is performed on both the MDM Administration console and the Samsung Android device.
On the MDM console, for the device, do the following:
1. In the "Android account" group, verify that "account management" is configured to "disable for the work email app".
2. Provision the user's email account for the work email app.
On the Samsung Android device, do the following:
1. Open Settings.
2. Tap "Accounts and backup".
3. Tap "Accounts".
4. Tap "Add account".
5. Verify that an account for the work email app cannot be added.
If on the MDM console "account management" is not disabled for the work email app, or on the Samsung Android device the user can add an account for the work email app, this is a finding.
V-92857
False
KNOX-09-000010
Review device configuration settings to confirm that users are prevented from adding personal email accounts to the work email app.
This procedure is performed on both the MDM Administration console and the Samsung Android device.
On the MDM console, for the device, do the following:
1. In the "Android account" group, verify that "account management" is configured to "disable for the work email app".
2. Provision the user's email account for the work email app.
On the Samsung Android device, do the following:
1. Open Settings.
2. Tap "Accounts and backup".
3. Tap "Accounts".
4. Tap "Add account".
5. Verify that an account for the work email app cannot be added.
If on the MDM console "account management" is not disabled for the work email app, or on the Samsung Android device the user can add an account for the work email app, this is a finding.
M
3495