Monterey - Disable TouchID for Unlocking the Device

Information

TouchID enables the ability to unlock a Mac system with a user's fingerprint.

TouchID _MUST_ be disabled for "Unlocking your Mac" on all macOS devices that are capable of using Touch ID.

The system _MUST_ remain locked until the user establishes access using an authorized identification and authentication method.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.applicationaccess:
allowFingerprintForUnlock:
False

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, 800-53|AC-11b., CCE|CCE-91083-6, CCI|CCI-000056

Plugin: Unix

Control ID: 606a6ab60d6a2934959edf815bcd1b66eee221a5dbc82d85d13d29814833333f