Android Security Settings

  1. Go to Policy and select a policy profile.
  2. Click Device > Android Security Settings and review the available classifications and risk levels.
  3. Click Device > Android Security Settings and set the Risk Level for these classifications:

    Classification

    Description

    Risk Level

    Rooted Device Set a Risk level if the device is identified as a rooted device.
    • No Risk (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    Verified boot is disabled

    Set a Risk Level if the verified boot feature is disabled on the device.

    • Low (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    SELinux Permissive mode

    Set a Risk Level if SELinux policy is not enabled on the device.

    • Low (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    Device Encryption disabled

    Set a Risk Level if device encryption is disabled.

    • Low (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    Unknown Sources Enabled

    Set a Risk Level if the device allows app installations from sources other than the play store.

    • Medium (No Device Alert) (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    USB debugging enabled

    Set a Risk Level if the device allows USB debugging.

    • Medium (No Device Alert) (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    Notification Permission is set to OFF

    Set a Risk Level if notification permission is disabled for the Mobile Security Protect app on the device.

    • Low (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    Location Permission is set to OFF

    Set a Risk Level if device location permission is disabled for the Mobile Security application on the device.

    • Low (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    Qualcomm Hexagon Vulnerability *

    Set a Risk Level based on Qualcomm Hexagon vulnerability.

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    VPN lock down

    Set a Risk Level if the Block connections without VPN setting is disabled for the device.

    • Medium (Device Alert) (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    MediaTek Audio DSP Vulnerability *

    Set a Risk Level for the CVE-2021-0673 vulnerability.

    The system diverts the CVE MediaTek debugging framework for audio drivers to escalate local process privileges.

    • No Risk (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    * To view the setting, contact Check Point Support.