Monterey - Set Account Lockout Time to 15 Minutes

Information

The macOS _MUST_ be configured to enforce a lockout time period of at least 15 minutes when the maximum number of failed logon attempts is reached.

This rule protects against malicious users attempting to gain access to the system via brute-force hacking methods.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.mobiledevice.passwordpolicy:
minutesUntilFailedLoginReset:
15

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, 800-53|AC-7b., CCE|CCE-91030-7, CCI|CCI-002238

Plugin: Unix

Control ID: 2e9562a3a789a71be27b1f7c61957922c7728e89bef54de7fff8456f0f82317f