Big Sur - Enforce Screen Saver Password

Information

Users _MUST_ authenticate when unlocking the screen saver.

The screen saver acts as a session lock and prevents unauthorized users from accessing the current user's account.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.screensaver:
askForPassword:
True

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, 800-53|AC-11b., CCE|CCE-85443-0, CCI|CCI-000056, STIG-ID|APPL-11-000002

Plugin: Unix

Control ID: e2b53b124c7e65687ddcb0793cc7595bb1e3ff6fb0d99b7d9ace9e931c9eb2fa