Big Sur - Disable TouchID for Unlocking the Device

Information

TouchID enables the ability to unlock a Mac system with a user's fingerprint.

TouchID _MUST_ be disabled for "Unlocking your Mac" on all macOS devices that are capable of using Touch ID.

The system _MUST_ remain locked until the user establishes access using an authorized identification and authentication method.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.applicationaccess:
allowFingerprintForUnlock:
False

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, 800-53|AC-11b., CCE|CCE-85451-3, CCI|CCI-000056

Plugin: Unix

Control ID: e4aa31872c7823e0a6d1998144f7e730bf58f18f51fac0bbea1b94ffaae96fb0