STIGUI
V-284844CAT I — High severitySV-284844r1240699_rule

Google Android 17 must be configured to disable Private Space use.

Rule version GOOG-17-010000 · STIG v1 · 2026-07-09

Discussion

Private Space is an Android feature that provides a separate encrypted container on the mobile device. Apps in Private Space show up in a separate container in the launcher and are hidden from the "Recents" view, notifications, settings, and other apps when the private space is locked. In addition, an MDM server allow list or block list cannot control the installation of apps into Private Space. Malware and other unauthorized apps could be installed on a DoW mobile device, which could lead to the compromise of DoW sensitive information or to an attack on the DoW network.

SFR ID: FMT_MOF_EXT.1.2 #47

Check

Review the Google Android 17 work profile configuration settings to confirm that Private Space is disabled.

This procedure is performed only on the EMM administration console.

On the EMM console:

COBO:

1. Open "Set user restrictions". 2. Verify that "Disallow add private profile" is set to "ON".

COPE:

1. Open "Set user restrictions". 2. Verify that "Disallow add private profile" is set to "ON".

If on the EMM console "Disallow add private profile" is not selected, this is a finding.

Fix

Configure the Google Android 17 device to disable Private Space.

On the EMM console:

COBO:

1. Open "Set user restrictions". 2. Toggle "Disallow add private profile" to "ON".

COPE:

1. Open "Set user restrictions". 2. Toggle "Disallow add private profile" to "ON".

Configuration API: DISALLOW_ADD_PRIVATE_PROFILE

Identifiers

Group ID
V-284844
Group title
PP-MDF-994000
Rule ID
SV-284844r1240699_rule
Check ID
C-89414r1240450_chk
Fix ID
F-89319r1240451_fix