2.6.3 Ensure Automatic Login Is Disabled

Information

The automatic login feature saves a user's system access credentials and bypasses the login screen. Instead, the system automatically loads to the user's desktop screen.

Disabling automatic login decreases the likelihood of an unauthorized person gaining access to a system.

Solution

Run the following command to disable automatic login:

% /usr/bin/sudo /usr/bin/defaults delete /Library/Preferences/com.apple.loginwindow autoLoginUser

Impact:

If automatic login is not disabled, an unauthorized user could gain access to the system without supplying any credentials.

See Also

https://workbench.cisecurity.org/benchmarks/17466

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CSCv7|4.2

Plugin: Unix

Control ID: 0999c70e5705c297a6130f73a3dabfb7eaf848ac996ebfba05127a0b1b2c0d3c