5.9 Disable automatic login

Information

The automatic login feature saves a user's system access credentials and bypasses the login screen, instead the system automatically loads to the user's desktop screen.

Rationale:

Disabling automatic login decreases the likelihood of an unauthorized person gaining access to a system.

Impact:

If Automatic login is not disabled an unauthorized user could login without supplying a user password or credential.

Solution

Perform the following to implement the prescribed state:
Run the following command in Terminal:

sudo defaults delete /Library/Preferences/com.apple.loginwindow autoLoginUser

See Also

https://workbench.cisecurity.org/files/3092

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-14a.

Plugin: Unix

Control ID: 3357fe725f6617d0b3bb7af519fcda53059f6613a9ca4e2a26c096e56f333072