An enterprise mobility management (EMM), also known as mobile device management (MDM), system can be used to provision policies to mobile devices to control aspects of their allowed behavior.
Domain | ID | Name | Use | |
---|---|---|---|---|
Mobile | T1517 | Access Notifications |
On Android devices with a managed work profile (enterprise managed portion of the device), the |
|
Mobile | T1476 | Deliver Malicious App via Other Means |
On iOS, the |
|
Mobile | T1458 | Exploit via Charging Station or PC |
Enterprise policies should prevent enabling USB debugging on Android devices unless specifically needed (e.g., if the device is used for application development). |
|
Mobile | T1417 | Input Capture |
When using Samsung Knox, third-party keyboards must be explicitly added to an allow list in order to be available to the end-user.[2] |
|
Mobile | T1516 | Input Injection |
An EMM/MDM can use the Android |
|
Mobile | T1411 | Input Prompt |
An EMM/MDM can use the Android |
|
Mobile | T1461 | Lockscreen Bypass |
Enterprises can provision policies to mobile devices to require a minimum complexity (length, etc.) for the device passcode. Enterprises can provision policies to mobile devices to cause the device to wipe all data if an incorrect passcode is entered too many times. Both policies would mitigate brute-force, guessing, or shoulder surfing of the device passcode. If desired, enterprises can provision policies to mobile devices to disallow biometric authentication. However, biometric authentication can help make "using a longer, more complex passcode far more practical because you don't need to enter it as frequently."[3] |
|
Mobile | T1465 | Rogue Wi-Fi Access Points |
Enterprise policies could be provisioned to devices to control the Wi-Fi access points that they are allowed to connect to. |
|
Mobile | T1513 | Screen Capture |
Enterprise policies should block access to the Android Debug Bridge (ADB) by preventing users from enabling USB debugging on Android devices unless specifically needed (e.g., if the device is used for application development). An EMM/MDM can use the Android |