Skip to content

The macOS system logon window must be configured to prompt for username and password, rather than show a list of users.

An XCCDF Rule

Description

<VulnDiscussion>The logon window must be configured to prompt all users for both a username and a password. By default, the system displays a list of known users at the logon screen. This gives an advantage to an attacker with physical access to the system, as the attacker would only have to guess the password for one of the listed accounts.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-252538r877377_rule
Severity
Low
References
Updated



Remediation - Manual Procedure

This setting is enforced using the "Login Window Policy" configuration profile.