6.1.3 Disable guest account login

Information

Disabling the guest account mitigates the risk of an untrusted user doing basic reconnaissance and possibly using privilege escalation attacks to take control of the system.

Solution

Perform the following to implement the prescribed state:
1. Open System Preferences
2. Select Users & Groups
3. Select Guest User
4. Uncheck Allow guests to log in to this computer
Alternatively:
1. Run the following command in Terminal:
sudo defaults write /Library/Preferences/com.apple.loginwindow GuestEnabled -bool NO

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Unix

Control ID: 8a2913e77b48777852612ce213dbf6486880544d06f3a7db145a2bbd7883816d