Big Sur - Enable Recovery Lock

Information

A recovery lock password _MUST_ be enabled and set.

Single user mode, recovery mode, the Startup Manager, and several other tools are available on macOS by holding down specific key combinations during startup. Setting a recovery lock restricts access to these tools.

NOTE: Recovery lock passwords are not supported on Intel devices. This rule is only applicable to Apple Silicon devices.

NOTE: This feature was added in macOS Big Sur version 11.5.

Solution

NOTE: The SetRecoveryLock command can be used to set a Recovery Lock password.

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CCE|CCE-85483-6

Plugin: Unix

Control ID: bd604e9ec2f4ffd2207f4f5d33420046de2e20137313419cc895303a60f630a9