Big Sur - Disable TouchID for Unlocking the Device

Information

TouchID enables the ability to unlock a Mac system with a user's fingerprint.

TouchID _MUST_ be disabled for "Unlocking your Mac" on all macOS devices that are capable of using Touch ID.

The system _MUST_ remain locked until the user establishes access using an authorized identification and authentication method.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.applicationaccess:
allowFingerprintForUnlock:
False

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, 800-53|AC-11b., CCE|CCE-85451-3, CCI|CCI-000056

Plugin: Unix

Control ID: ac694bac9ddb2155877eee048c959746fcb142b79240a35e113dae4e9972f924