Apple iPadOS 18 must be configured to disable multiuser modes.

STIG ID: AIOS-18-009800  |  SRG: PP-MDF-333290 |  Severity: medium |  CCI: CCI-002110 |  Vulnerability Id: V-268018

Vulnerability Discussion

Multiuser mode allows multiple users to share a mobile device by providing a degree of separation between user data. To date, no mobile device with multiuser mode features meets DOD requirements for access control, data separation, and nonrepudiation for user accounts. In addition, the MDFPP does not include design requirements for multiuser account services. Disabling multiuser mode mitigates the risk of not meeting DOD multiuser account security policies.

SFRID: FMT_SMF.1.1 #47a

Check

Verify multiuser mode (shared iPad) is disabled in the MDM console for iPadOS devices. This requirement is not applicable for iOS devices.

If multiuser mode is not disabled in the MDM console for iPadOS devices, this is a finding.

Fix

Disable multiuser mode (shared iPad) in the MDM console for iPadOS devices.