Monterey - Disable TouchID for Unlocking the Device

Information

TouchID enables the ability to unlock a Mac system with a user's fingerprint.

TouchID _MUST_ be disabled for "Unlocking your Mac" on all macOS devices that are capable of using Touch ID.

The system _MUST_ remain locked until the user establishes access using an authorized identification and authentication method.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.applicationaccess:
allowFingerprintForUnlock:
False

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, 800-53|AC-11b., CCE|CCE-91083-6, CCI|CCI-000056

Plugin: Unix

Control ID: 8f1222393eb900231fb756c524e04a7a4408dc585055b4b7c2560ce5d0e07894