Catalina - Disable FileVault Automatic Login

Information

If FileVault is enabled, automatic login _MUST_ be disabled, so that both FileVault and login window authentication are required.

The default behavior of macOS when FileVault is enabled is to automatically log in to the computer once successfully passing your FileVault credentials.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.loginwindow:
DisableFDEAutoLogin:
True

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-2(11), 800-53|AC-3, 800-53|CM-6b., 800-53|IA-5(13), CCE|CCE-84754-1, CCI|CCI-000366, STIG-ID|AOSX-15-002066

Plugin: Unix

Control ID: 78d1e319eb43c7160323ecd18e56ee2cddf80333df2dd60c036504a7dfa812bf