Implementation examples
17 examples referencing MDM
- MP.L2-3.8.8[a]
No identifiable owner, no port: found drives go in the amnesty bin
AO coverage. Addresses the Shared Media objective: use of portable storage devices is prohibited when the device has no identifiable owner. What identifiable owner means here. A portable storage…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - MP.L2-3.8.2[a]
Only the enclave roster can open the cabinet or mount an encrypted drive
AO coverage. Addresses the Media Access objective: access to CUI on system media is limited to authorized users. One authoritative roster. The enclave roster — the same identity group that gates…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - SI.L2-3.14.4[a]
Definitions update automatically within hours; stale-definition devices lose CUI access
AO coverage. Addresses the single Update Malicious Code Protection objective across every location designated for malicious code protection. Automatic by default. Signature and intelligence updates…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - SC.L2-3.13.12[a] [b] [c]
No remote activation of cameras or mics; visible indication required wherever CUI is discussed
AO coverage. Addresses all three Collaborative Device Control objectives: identifying the devices, providing indication of use, and prohibiting remote activation. Devices identified [a]. Laptop…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - SC.L2-3.13.7[a]
Always-on full tunnel with local LAN access and NIC bridging disabled in client policy
AO coverage. Addresses the single Split Tunneling objective for managed endpoints that can reach CUI. Client posture. The VPN profile is deployed by MDM, set to always-on with user-logon connect, and…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - CM.L2-3.4.8[a] [b] [c]
Deny-all, permit-by-exception on CUI endpoints after 60 days in audit mode
AO coverage. Addresses all three Application Execution Policy objectives: the policy choice is specified [a], the software allowed to execute is specified [b], and allow-listing is implemented as…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - CM.L2-3.4.7[a] [b] [c] [d] [e] [f] [g] [h] [i] [j] [k] [l] [m] [n] [o]
Five lists, one review: essential programs, functions, ports, protocols, and services
AO coverage. Addresses all fifteen Nonessential Functionality objectives by treating the five categories separately — for each of programs, functions, ports, protocols, and services we define what is…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.11[a]
Masked entry on every surface, including kiosks, scanners, and the mirrored conference display
AO coverage. Addresses the single Obscure Feedback objective across the authentication surfaces enumerated below. Surfaces in scope. Workstation and kiosk logon, virtual desktop sign-in, internal web…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.1[a] [b] [c]
One naming standard for people, svc- identities, and device records
AO coverage. Addresses all three Identification objectives: users, processes acting on behalf of users, and devices that access the system. Users. Person accounts follow with a numeric suffix on…
ControlVerdict Corpus@cv-corpusJul 31, 2026Not enough signal88% · 2 - AC.L2-3.1.21[a] [b] [c]
No org USB on home PCs; portable media only on managed endpoints
AO coverage. Addresses all Portable Storage Use objectives regarding external systems. Limit. Portable storage that may hold CUI is org-issued, hardware-encrypted, and only mountable on managed…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.18[a] [b] [c]
Only MDM-enrolled mobiles; USB/debug restricted on CUI phones
AO coverage. Addresses all Mobile Device Connection objectives for devices that access CUI. Control connection. CUI mail/files require Intune enrollment or app-protection policy. Jailbroken/rooted…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.10[a] [b] [c]
Screen lock ≤15 minutes with pattern-hiding on CUI endpoints
AO coverage. Addresses all Session Lock objectives for in-scope endpoints. Windows. Intune profile: idle lock at 15 minutes or less, password/PIN required to resume, lock screen does not preview CUI…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.9[a] [b]
CUI rules banner before enclave session and on shared workstations
AO coverage. Addresses both Privacy & Security Notices objectives for CUI rules. Notices. Before first daily access to enclave apps, users accept an IdP Terms of Use stating CUI handling rules,…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.6[a] [b]
Day-to-day work on standard accounts; elevate only for admin tasks
AO coverage. Addresses both Non-privileged Account Use objectives. Standard accounts. Email, Office, and CUI SaaS are used from the user’s non-privileged account. Local admin rights are removed from…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.12[a] [b] [c]
Compliant-device VPN or SSO only; session recording for privileged remote admin
AO coverage. Claims objectives [a], [b], and [c] (permit, identify types, and control remote access). Objective [d] (monitor sessions) is only partially covered here: VPN connect/disconnect and…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - MP.L2-3.8.3[a] [b]
Full-disk encryption plus cryptographic erase; destroy when CE cannot be verified
AO coverage. Addresses all media sanitization objectives for this practice. Prerequisite. All in-scope endpoints use full-disk encryption with keys escrowed to the directory/MDM. Removable media that…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.4[a]
Network access requires FIDO2 or certificate; OTP not accepted for VPN or SSO
AO coverage. Addresses all replay-resistant authentication objectives for this practice. Policy. Authentication strength for all CUI applications and the VPN requires a phishing-/replay-resistant…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet