Big Sur - FileVault Authorized Users

Information

macOS _MUST_ be configured to only allow authorized users to unlock FileVault upon startup.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remove the user that is not authorized to unlock FileVault using the fdesetup command.

[source,bash]
----
/usr/bin/fdesetup remove -user NOT_AUTHORIZED_USERNAME
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(11), CCE|CCE-85311-9, CCI|CCI-002143, STIG-ID|APPL-11-000032

Plugin: Unix

Control ID: 5ecbbcb9d02d47daac48d931a1331ccd15444cc7f75d7ff905d8d86a1698a5bc