Watchtower Docs
ReferenceCheck catalog

iOS/iPadOS (Intune-managed)

All 45 iOS/iPadOS (Intune-managed) checks - what each one checks, why, and the access used to evaluate it.

45 checks. Column "Access used" lists the application permissions and collected data sources this check's evaluation reads; "None" means Watchtower reads no tenant data for it.

CheckSeverityWhat it checksWhy it mattersAccess used
Ensure External Intelligence Integration Sign-In Is Disabled
wt.ios.ai.external-intelligence-disabled
HIGHChecks that iOS devices are configured to block sign-in to external AI intelligence services (such as third-party AI integrations in Apple Intelligence), preventing device data from being processed by external AI providers.External AI integrations can transmit device content - including messages, documents, and screen context - to third-party AI providers outside the organisation's data governance controls. This creates an unaudited data exfiltration pathway for sensitive corporate information processed on managed devices.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Writing Tools (Apple Intelligence) Are Disabled
wt.ios.ai.writing-tools-disabled
LOWChecks that Apple Intelligence Writing Tools are disabled on managed iOS devices, preventing on-device and cloud AI processing of user-typed content in managed applications.Writing Tools process text in real time - including email drafts, messages, and document content - potentially sending context to Apple's servers. On managed devices handling sensitive corporate data, this creates a risk of inadvertent disclosure of confidential information to external AI infrastructure.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Screenshots and Screen Recording Are Disabled
wt.ios.apps.screenshots-disabled
LOWChecks that iOS devices are configured to prevent users from taking screenshots or screen recordings, protecting sensitive corporate content displayed on managed devices.Screenshots and screen recordings are a common vector for data exfiltration from mobile devices - users or malicious applications can capture sensitive content from corporate apps and transfer the images through personal channels. Disabling this capability on managed devices reduces the risk of sensitive data being captured and shared.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Encrypted Backups Are Enforced
wt.ios.backup.encrypted-backup-enforced
HIGHChecks that iTunes/Finder backups for managed iOS devices are configured to require encryption, ensuring backup files stored on computers are protected from unauthorised access.Unencrypted device backups stored on a user's computer expose all corporate data on the device - including emails, contacts, and app data - to anyone with physical or remote access to the backup files. Encrypting backups ensures corporate data remains protected even when stored outside the corporate MDM environment.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure iCloud Backup Is Disabled
wt.ios.backup.icloud-backup-disabled
HIGHChecks that iCloud backup is disabled on managed iOS devices, preventing corporate data stored on the device from being automatically synced to Apple's iCloud servers.iCloud backups can contain the full contents of managed corporate applications - emails, documents, authentication tokens, and app data - and store them in Apple's cloud infrastructure. This bypasses the organisation's data governance controls and creates an unmanaged copy of corporate data accessible outside the MDM environment.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Jailbroken Devices Are Blocked
wt.ios.compliance.jailbreak-blocked
CRITICALChecks that the Intune compliance policy marks jailbroken iOS devices as non-compliant, ensuring devices with removed security restrictions are denied access to corporate resources.Jailbroken devices have iOS security controls - code signing, sandboxing, and system integrity protection - removed or disabled. These devices can run unsigned code, access any app's data, and bypass MDM restrictions, making them vectors for malware, credential theft, and data exfiltration that circumvent all MDM-enforced controls.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Minimum iOS Version Is Enforced
wt.ios.compliance.min-os-version
HIGHChecks that managed iOS devices meet the minimum operating system version requirement defined in the Intune compliance policy, ensuring devices run a version with current security patches.Older iOS versions contain known, publicly-disclosed vulnerabilities that are exploited by spyware, malware, and targeted attack tools. Enforcing a minimum OS version ensures devices on the corporate network have security patches applied, reducing the risk of exploitation through unpatched vulnerabilities.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure AirDrop Is Disabled
wt.ios.data.airdrop-unmanaged
HIGHChecks that AirDrop is disabled on managed iOS devices, preventing wireless file transfer to nearby unmanaged devices and unknown recipients.AirDrop allows any nearby iOS or macOS device to receive files from managed devices without authentication when set to Everyone. This creates a trivial data exfiltration path - a user can wirelessly transfer corporate documents, photos, or files to any personal device or to a nearby attacker's device without leaving an audit trail.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Access to Network Drives in Files App Is Blocked
wt.ios.data.files-network-drive-disabled
LOWChecks that managed iOS devices are configured to block access to network drives through the Files app, preventing users from connecting to SMB shares or NAS devices.Unrestricted network drive access from mobile devices allows users to connect to arbitrary network storage - including personal NAS devices or attacker-controlled SMB shares - and transfer corporate data outside the MDM management boundary and corporate DLP controls.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Access to USB Drives in Files App Is Blocked
wt.ios.data.files-usb-drive-disabled
LOWChecks that managed iOS devices are configured to block access to USB drives through the Files app, preventing physical data transfer to external storage media.USB drive access from iOS via the Files app allows users to copy corporate documents to external flash drives or portable hard drives, bypassing MDM data loss prevention controls. Physical media exfiltration is difficult to detect and leaves no network-based audit trail.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Sending Data from Managed Apps to Unmanaged Apps Is Blocked
wt.ios.data.managed-to-unmanaged-blocked
HIGHChecks that the Intune App Protection Policy restricts data transfer from managed corporate apps to unmanaged personal apps, preventing copy-paste and open-in operations that move data outside the management boundary.Without this restriction, users can copy corporate email, documents, or attachments directly into unmanaged personal apps such as personal notes, social media, or file managers. Once data leaves the managed app boundary it is no longer subject to DLP policies, remote wipe, or access controls.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Receiving Data from Unmanaged Apps in Managed Apps Is Blocked
wt.ios.data.unmanaged-to-managed-blocked
HIGHChecks that the Intune App Protection Policy blocks receiving data from unmanaged personal apps into managed corporate apps, preventing untrusted content from being pasted or opened within the managed app boundary.Allowing unmanaged apps to inject data into managed apps creates a path for introducing malicious content - such as weaponised documents or credential-harvesting links - directly into corporate applications. It also undermines data classification by mixing unverified personal content with controlled corporate data.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Apple Watch Wrist Detection Is Enabled
wt.ios.devices.apple-watch-wrist-detection
LOWChecks that paired Apple Watches have wrist detection enabled, ensuring the watch automatically locks when removed from the wrist and requires authentication to resume use.Without wrist detection, an Apple Watch remains unlocked after being removed from the wearer's wrist. A lost or stolen watch would remain accessible, exposing notifications, messages, health data, and any apps that do not enforce their own authentication.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure New Device Proximity Setup Is Disabled
wt.ios.devices.new-device-proximity-disabled
LOWChecks that the proximity-based device setup feature is disabled on managed iOS devices, preventing automatic credential and settings transfer to a new nearby iPhone.Proximity setup transfers iCloud credentials, Wi-Fi passwords, and configuration data to a new device via Bluetooth. On a managed device, this could expose corporate account credentials and network configurations to an unmanaged personal replacement device, bypassing MDM enrolment.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Pairing with Non-Configurator Hosts Is Disabled
wt.ios.devices.non-configurator-pairing-disabled
MEDIUMChecks that managed iOS devices are restricted from pairing with computers that are not designated Apple Configurator hosts, preventing unauthorised USB connections to unmanaged workstations.USB pairing with arbitrary computers exposes the device to iTunes/Finder backups, sideloaded apps, and forensic extraction tools. An attacker with brief physical access to a managed device can pair it with a controlled computer and extract corporate data or install malicious provisioning profiles without the user's awareness.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Password AutoFill Requires Biometric Authentication
wt.ios.devices.password-autofill-biometric
HIGHChecks that iOS Password AutoFill requires biometric authentication before filling saved credentials, ensuring that AutoFill cannot be used by someone who has unlocked the device by other means.If AutoFill fills credentials without biometric confirmation, anyone who unlocks the device - including through coercion, observation, or a compromised PIN - can immediately authenticate to corporate applications and websites without additional verification. Requiring Face ID or Touch ID adds a discrete authentication step that is both harder to observe and harder to coerce.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Modification of Cellular Data App Settings Is Restricted
wt.ios.general.cellular-settings-disabled
LOWChecks that users are prevented from modifying per-app cellular data settings on managed iOS devices, ensuring that corporate apps retain network access and personal apps cannot be granted unrestricted mobile data.If users can modify cellular data permissions per app, they may disable network access for security tools such as the MDM agent or Defender for Endpoint, or enable mobile data for apps that should be Wi-Fi-only. This creates gaps in monitoring coverage and can incur unintended corporate data costs.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Users Cannot Install Configuration Profiles
wt.ios.general.config-profile-install-disabled
HIGHChecks that users cannot manually install configuration profiles on managed iOS devices, preventing unauthorised profiles from overriding MDM-enforced settings or installing untrusted certificate authorities.A manually installed configuration profile can add a rogue CA certificate to the trust store, enabling man-in-the-middle interception of corporate TLS traffic. Profiles can also override MDM restrictions, unlock features the corporate policy has disabled, or enrol the device in a second MDM without the user understanding the implications.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Date and Time Are Set Automatically
wt.ios.general.date-time-automatic
LOWChecks that managed iOS devices are configured to set the date and time automatically via network time, preventing users from manually adjusting the clock.Accurate system time is required for certificate validation, Kerberos/NTLM authentication, and the integrity of security audit logs. An incorrect clock can cause certificate expiry errors, break MFA token validation, and introduce misleading timestamps into incident response timelines.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Erase Content and Settings Is Disabled
wt.ios.general.erase-settings-disabled
HIGHChecks that the Erase All Content and Settings option is disabled on managed iOS devices, preventing users from wiping the device and removing MDM enrolment outside of an IT-initiated process.A user-initiated factory reset removes the MDM profile, taking the device outside the management boundary. Corporate data cached on the device is destroyed without an IT-controlled wipe record, and the device becomes unmanaged, bypassing all MDM controls. This can also be used deliberately to evade detection after a policy violation.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Users Cannot Create VPN Configurations
wt.ios.general.vpn-install-disabled
HIGHChecks that users are prevented from creating VPN configurations on managed iOS devices, ensuring all network traffic routes through IT-approved connections rather than user-defined tunnels.A user-created VPN can route all device traffic - including corporate email and app data - through an untrusted or attacker-controlled endpoint, bypassing corporate web filtering, DLP inspection, and network monitoring. It can also be used to circumvent geo-restrictions or split-tunnel controls put in place by IT.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure iCloud Drive Is Disabled
wt.ios.icloud.drive-disabled
HIGHChecks that iCloud Drive is disabled on managed iOS devices, preventing documents and data from being synchronised to Apple's cloud storage outside the corporate data boundary.iCloud Drive stores files in Apple's infrastructure under the user's personal Apple ID, beyond the reach of corporate DLP controls, eDiscovery, and MDM remote wipe. Corporate documents saved to iCloud Drive persist even after the device is unenrolled, and are accessible from personal devices not subject to MDM management.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Handoff Is Disabled
wt.ios.icloud.handoff-disabled
LOWChecks that Handoff is disabled on managed iOS devices, preventing in-progress activities and clipboard content from being relayed to other Apple devices signed into the same Apple ID.Handoff transmits activity state - including open documents, clipboard contents, and browser URLs - over Bluetooth and iCloud to nearby Apple devices. This creates a channel for corporate data to transfer to personal unmanaged Macs or iPads without user interaction, bypassing MDM and DLP controls.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure iCloud Keychain Is Disabled
wt.ios.icloud.keychain-disabled
HIGHChecks that iCloud Keychain is disabled on managed iOS devices, preventing saved passwords, passkeys, and credit card data from synchronising to Apple's cloud and other personal devices.iCloud Keychain synchronises credentials across all devices signed into the same Apple ID. Corporate credentials saved on a managed device would be replicated to personal unmanaged devices outside the MDM boundary. A compromised Apple ID would give an attacker access to all stored corporate passwords.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure iCloud Storage of Managed App Data Is Disabled
wt.ios.icloud.managed-apps-icloud-disabled
HIGHChecks that managed applications are prevented from storing data in iCloud, ensuring corporate app data remains on the device and within the MDM management boundary rather than in Apple's cloud infrastructure.When managed apps store data in iCloud, that data leaves the corporate boundary and is replicated to any personal device signed into the same Apple ID. MDM remote wipe can remove the app from the managed device but cannot delete data already synchronised to iCloud, leaving corporate information accessible after unenrolment.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Control Center Is Not Accessible on the Lock Screen
wt.ios.lockscreen.control-center-disabled
HIGHChecks that Control Center cannot be opened from the iOS lock screen, preventing unauthenticated access to network toggles, Airplane Mode, and other system controls without unlocking the device.Control Center accessed from the lock screen allows an unauthenticated person to enable Airplane Mode, disabling MDM communication and remote wipe capability, or to toggle Wi-Fi and Bluetooth in ways that could bypass network monitoring. Restricting lock screen access ensures device controls require authentication.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Notification Center Is Not Accessible on the Lock Screen
wt.ios.lockscreen.notifications-disabled
HIGHChecks that the Notification Center is inaccessible from the iOS lock screen, preventing sensitive corporate notifications from being read by anyone who picks up the device without unlocking it.Lock screen notifications can expose email subject lines, message previews, MFA codes, and approval request details to anyone with physical access to the device. Attackers with brief access to a locked device can read notification content to gather intelligence, intercept one-time codes, or approve fraudulent authentication requests.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Password Proximity Requests Are Disabled
wt.ios.lockscreen.password-proximity-disabled
HIGHChecks that managed iOS devices cannot request passwords from nearby devices, preventing the iOS proximity password-sharing prompt from appearing and potentially exposing saved credentials to adjacent unmanaged devices.The proximity password request feature prompts nearby Apple devices to offer stored credentials over Bluetooth. On a managed device, this could expose corporate account passwords to an employee's personal unmanaged device held nearby, moving credentials outside the managed app and keychain boundary.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure USB Accessories Are Not Allowed When Device Is Locked
wt.ios.lockscreen.usb-accessories-disabled
HIGHChecks that USB accessories are blocked from communicating with a locked iOS device, ensuring the USB Restricted Mode protection cannot be bypassed by connecting a hardware accessory.USB Restricted Mode is an iOS security feature that disables USB data communication one hour after the device was last unlocked, protecting against GrayKey and similar forensic extraction tools. Allowing USB accessories while locked can circumvent this protection, providing a window for data extraction from a physically seized device.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Mail Drop Is Disabled
wt.ios.mail.maildrop-disabled
LOWChecks that Mail Drop is disabled on managed iOS devices, preventing the native Mail app from uploading large email attachments to iCloud for recipient download via a public link.Mail Drop uploads attachment content to iCloud and distributes it via a time-limited public link accessible to anyone with the URL. Corporate documents sent via Mail Drop are stored in Apple's cloud outside the corporate boundary and are delivered through a mechanism that bypasses corporate email DLP inspection.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Moving Messages Between Accounts Is Disabled
wt.ios.mail.move-messages-disabled
LOWChecks that users cannot move email messages between accounts in the iOS Mail app, preventing corporate emails from being copied into personal email accounts on the same device.Moving messages from a managed corporate mailbox to a personal email account on the same device removes them from the corporate mail system, bypassing archiving, eDiscovery, and retention policies. It also transfers email content - including sensitive attachments - into an unmanaged account not subject to corporate DLP controls.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Notes App Transcription Summaries Are Disabled
wt.ios.mail.notes-summary-disabled
LOWChecks that on-device AI transcription summaries in the Notes app are disabled on managed iOS devices, preventing the system from processing and summarising note content through Apple Intelligence models.Notes app transcription summaries are generated by Apple Intelligence, which may process content using Apple infrastructure. Enabling summaries for notes that contain corporate information - meeting notes, project plans, credentials - exposes that content to on-device and potentially server-side AI processing outside organisational control.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Mail App AI Summaries Are Disabled
wt.ios.mail.summary-disabled
LOWChecks that the Mail app AI summary feature is disabled on managed iOS devices, preventing Apple Intelligence from generating automated email previews that process corporate email content.Apple Intelligence email summaries process message content on-device and may use Apple servers for enhanced summarisation. Corporate emails can contain sensitive information - contracts, financial data, personally identifiable information - that should not be fed into AI processing pipelines outside organisational governance and data classification controls.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Maximum Grace Period Is Configured
wt.ios.passcode.grace-period
HIGHChecks that the passcode grace period on managed iOS devices is set to an appropriate value, controlling how long after the screen dims the device can be unlocked without re-entering the passcode.A long grace period allows the device to be woken up and accessed without re-authentication for an extended time after it was last used. This means someone who picks up a recently used device can access all data without the passcode, negating the protection provided by auto-lock.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Screen Lock Is Configured for Inactivity
wt.ios.passcode.inactivity-lock
HIGHChecks that managed iOS devices lock the screen after a defined period of inactivity, reducing the window during which an unattended unlocked device can be accessed without authentication.An unlocked screen left unattended provides an open window for anyone nearby to access all apps, data, and settings. Short auto-lock intervals limit the exposure time in environments such as offices, cafes, and public transport where devices are frequently left on desks or tables.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Maximum Passcode Attempt Lockout Is Configured
wt.ios.passcode.lockout-threshold
HIGHChecks that managed iOS devices are configured to lock or wipe after a maximum number of failed passcode attempts, preventing unlimited passcode guessing against a physically acquired device.Without a failed-attempt lockout, an attacker with physical possession of the device can attempt passcodes indefinitely using automated tools. iOS natively supports wiping after ten failed attempts, but this must be enforced through the MDM profile to ensure users cannot change the setting or that supervised devices enforce it consistently.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Minimum Passcode Length Is Configured
wt.ios.passcode.minimum-length
HIGHChecks that managed iOS devices enforce a minimum passcode length, reducing the keyspace available for brute-force attacks and making offline attacks against the encrypted device infeasible.Short passcodes have a small number of possible combinations. A 4-digit PIN has only 10,000 combinations, which can be exhausted quickly when lockout is not enforced or can be estimated by an attacker with physical access using specialised hardware. A minimum of 6 characters significantly increases the attack cost.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Simple Passcodes Are Blocked
wt.ios.passcode.no-simple
HIGHChecks that simple passcodes are blocked on managed iOS devices, preventing users from setting easily guessable patterns such as sequential or repeated digits.Simple passcodes like 1234, 0000, or 1111 are among the first values tested in a brute-force attack. They can also be guessed by shoulder surfing, as the tap pattern is recognisable. Blocking simple passcodes forces users to choose codes that are harder to guess or observe.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure a Passcode Is Required
wt.ios.passcode.required
HIGHChecks that a passcode is required on managed iOS devices, ensuring the device cannot be unlocked without authentication and that data-at-rest encryption is active.iOS data-at-rest encryption is tied to the passcode. Without a passcode, the file system encryption key is not protected, making the device's data readable via forensic tools. A device without a passcode also allows anyone who picks it up to access all apps, email, and corporate data without authentication.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Personalized Advertising Is Disabled
wt.ios.privacy.advertising-limited
LOWChecks that personalised advertising is disabled on managed iOS devices, preventing Apple's advertising framework from using device activity and app usage data to target advertisements.The personalised advertising system collects behavioural signals - app usage patterns, purchase history, and device activity - to build an advertising profile. On a corporate device, these signals can include usage of business applications, inadvertently revealing organisational behaviour and technology choices to Apple's advertising network.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Diagnostic Data Sharing with Apple Is Disabled
wt.ios.privacy.diagnostics-disabled
LOWChecks that automatic diagnostic data sharing with Apple is disabled on managed iOS devices, preventing the device from transmitting crash reports, usage statistics, and system diagnostics to Apple's servers.Diagnostic data transmitted to Apple can include crash logs, application state information, and usage telemetry from apps running on the device. This data may contain fragments of corporate information or reveal details of internal application architectures and workflows to a third party outside the organisation's control.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Safari Cookie Settings Are Configured
wt.ios.safari.cookies-configured
HIGHChecks that Safari cookie settings are configured on managed iOS devices to block cross-site cookies, preventing third-party trackers from building browsing profiles from corporate device activity.Cross-site cookies are the primary mechanism used by advertising networks and analytics platforms to track users across websites. On a corporate device, this tracking can expose visited sites - including internal web portals - to third-party data brokers, and can be exploited in cross-site request forgery attacks.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Safari Fraud Warning Is Enabled
wt.ios.safari.fraud-warning-enabled
HIGHChecks that Safari's fraud warning feature is enabled on managed iOS devices, ensuring that known phishing and malicious websites trigger a warning before the user can proceed.Phishing via mobile browser is a common credential-harvesting technique. Safari's Safe Browsing integration checks URLs against databases of known malicious sites and warns users before they submit credentials. Disabling this feature removes a low-friction layer of protection against mobile phishing pages targeting corporate accounts.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Siri Is Disabled When Device Is Locked
wt.ios.siri.locked-disabled
HIGHChecks that Siri is disabled when the iOS device is locked, preventing voice queries from retrieving sensitive information or performing actions without the device being authenticated.Siri invoked from the lock screen can read out emails, messages, calendar entries, and contact information in response to voice queries without requiring passcode or biometric authentication. An attacker with brief physical access to a locked device can extract sensitive data or take actions - such as sending messages or making calls - using only voice commands.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles
Ensure Voice Dialing Is Disabled While Device Is Locked
wt.ios.siri.voice-dialing-disabled
HIGHChecks that voice dialing is disabled while the managed iOS device is locked, preventing calls from being placed through Siri without the device being authenticated.Voice dialing from a locked device allows anyone with physical access to make calls - including to premium-rate numbers, emergency services in non-emergency situations, or to numbers to facilitate social engineering - without unlocking the device. It bypasses the authentication requirement and can be exploited by someone holding a device momentarily.DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All - via iosAppProtectionPolicies, iosCompliancePolicies, iosConfigurationProfiles