Details
If FileVault is enabled, automatic login _MUST_ be disabled, so that both FileVault and login window authentication are required.
The default behavior of macOS when FileVault is enabled is to automatically log in to the computer once successfully passing your FileVault credentials.
Solution
This is implemented by a Configuration Profile.
mobileconfig profile info:
com.apple.loginwindow:
DisableFDEAutoLogin:
True
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Access Control, Configuration Management, Identification and Authentication.This control applies to the following type of system Unix.
References
- 800-53|AC-2(11)
- 800-53|AC-3
- 800-53|CM-6b.
- 800-53|IA-5(13)
- CCE|CCE-84754-1, CCI|CCI-000366
- STIG-ID|AOSX-15-002066