5.8 Disable automatic login

Information

The automatic login feature saves a user's system access credentials and bypasses the login screen, instead the system automatically loads to the user's desktop screen.

Rationale:

Disabling automatic login decreases the likelihood of an unauthorized person gaining access to a system.

Impact:

If Automatic login is not disabled an unauthorized user could gain access to the system without supplying any credentials.

Solution

Perform the following to set automatic login to off:
Graphical Method:

Open System Preferences

Select Users & Groups

Click the lock to authenticate

Select Login Options

Select Automatic login and set it to Off

Terminal Method:
Run the following command to disable automatic login:

$ sudo defaults delete /Library/Preferences/com.apple.loginwindow autoLoginUser

See Also

https://workbench.cisecurity.org/files/3197

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-14, CSCv7|4.2

Plugin: Unix

Control ID: 3f962d9993d055df0be53d9ad2dedca8a296f45d2e1681385b5d337b43e7245d