SV-228619r505856_rule
V-228619
PP-MDF-301220
GOOG-11-003700
CAT II
10
Configure the Google Android 11 device to disable backup to locally connected systems.
NOTE: On Restrictions, the backup features for Google are not in the framework.
On the EMM console:
1. Open "Device owner management" section.
2. Toggle "Enable backup service" to Off.
3. Open "User restrictions on parent".
4. Select "Disallow USB file transfer".
Review Google Android device configuration settings to determine if the capability to back up to a locally connected system has been disabled.
This validation procedure is performed on both the EMM Administration Console and the Android 11 device.
On the EMM console, do the following:
1. Open "Device owner management" section.
2. Verify that "Enable backup service" is toggled to Off.
3. Open "User restrictions on parent".
4. Verify that "Disallow USB file transfer" is toggled to On.
On the Android 11 device, do the following:
1. Plug a USB cable into Android 11 device and connect to a non-DoD network-managed PC.
2. Go to Settings >> Connected devices >> USB.
3. Ensure "No data transfer" is selected.
If the EMM console device policy is not set to disable the capability to back up to a locally connected system or on the Android 11 device, the device policy is not set to disable the capability to back up to a locally connected system, this is a finding.
V-228619
False
GOOG-11-003700
Review Google Android device configuration settings to determine if the capability to back up to a locally connected system has been disabled.
This validation procedure is performed on both the EMM Administration Console and the Android 11 device.
On the EMM console, do the following:
1. Open "Device owner management" section.
2. Verify that "Enable backup service" is toggled to Off.
3. Open "User restrictions on parent".
4. Verify that "Disallow USB file transfer" is toggled to On.
On the Android 11 device, do the following:
1. Plug a USB cable into Android 11 device and connect to a non-DoD network-managed PC.
2. Go to Settings >> Connected devices >> USB.
3. Ensure "No data transfer" is selected.
If the EMM console device policy is not set to disable the capability to back up to a locally connected system or on the Android 11 device, the device policy is not set to disable the capability to back up to a locally connected system, this is a finding.
M
4229