Catalina - Disable Root Login

Information

To assure individual accountability and prevent unauthorized access, logging in as root at the login window _MUST_ be disabled.

The macOS system _MUST_ require individuals to be authenticated with an individual authenticator prior to using a group authenticator, and administrator users _MUST_ never log in directly as root.

Solution

[source,bash]
----
/usr/bin/dscl . -create /Users/root UserShell /usr/bin/false
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, 800-53|IA-2(5), CCE|CCE-84783-0

Plugin: Unix

Control ID: 8d6d93238de87ea241db629f5312787c4c8a91f63c21cb351050ba6165e04614