5.8 Disable automatic login

Information

The automatic login feature saves a user's system access credentials and bypasses the login screen, instead the system automatically loads to the user's desktop screen.

Rationale:

Disabling automatic login decreases the likelihood of an unauthorized person gaining access to a system.

Impact:

If Automatic login is not disabled an unauthorized user could gain access to the system without supplying any credentials.

Solution

Perform the following to set automatic login to off:
Graphical Method:

Open System Preferences

Select Users & Groups

Click the lock to authenticate

Select Login Options

Select Automatic login and set it to Off

Terminal Method:
Run the following command to disable automatic login:

$ sudo defaults delete /Library/Preferences/com.apple.loginwindow autoLoginUser

See Also

https://workbench.cisecurity.org/files/3195

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-14, CSCv7|4.2

Plugin: Unix

Control ID: bd0d6149762c065b3d3cbec13af8aa859825f677822086759018073c7475e494