Monterey - Disable Unlock with Apple Watch During Setup Assistant

Information

The prompt for Apple Watch unlock setup during Setup Assistant _MUST_ be disabled.

Disabling Apple watches is a necessary step to ensuring that the information system retains a session lock until the user reestablishes access using an authorized identification and authentication procedures.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.SetupAssistant.managed:
SkipUnlockWithWatch:
True

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-20, 800-53|CM-7a., CCE|CCE-91002-6, CCI|CCI-000381

Plugin: Unix

Control ID: 795e579d774dbe61ef83141bd9154d2df5c87c4f6f3c2f8eb200fccac1a3c868