Catalina - Disable TouchID for Unlocking the Device

Information

TouchID enables the ability to unlock a Mac system with a user's fingerprint.

TouchID _MUST_ be disabled for "Unlocking your Mac" on all macOS devices that are capable of using Touch ID.

The system _MUST_ remain locked until the user establishes access using an authorized identification and authentication method.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.applicationaccess:
allowFingerprintForUnlock:
False

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CCE|CCE-84849-9

Plugin: Unix

Control ID: 0fc83477d8719e3ed5f0eebce0086dca8296a3315a286beb0ba783bea224ab13