APPL-12-005052 - The macOS system logon window must be configured to prompt for username and password, rather than show a list of users.

Information

The logon window must be configured to prompt all users for both a username and a password. By default, the system displays a list of known users at the logon screen. This gives an advantage to an attacker with physical access to the system, as the attacker would only have to guess the password for one of the listed accounts.

Solution

This setting is enforced using the 'Login Window Policy' configuration profile.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_12_V1R9_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-252538r991591_rule, STIG-ID|APPL-12-005052, Vuln-ID|V-252538

Plugin: Unix

Control ID: 483f12ed2c4be68a78823565fa6238578df3bec2dcb9cb5caa21edd428959ec1