The macOS system must disable the guest account.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
medium | V-268510 | SRG-OS-000364-GPOS-00151 | APPL-15-002063 | SV-268510r1034470_rule | 2025-02-20 | 1 |
Description |
---|
Guest access must be disabled. Turning off guest access prevents anonymous users from accessing files. |
ℹ️ Check |
---|
Verify the macOS system is configured to disable the guest account with the following command: /usr/bin/osascript -l JavaScript << EOS function run() { let pref1 = ObjC.unwrap($.NSUserDefaults.alloc.initWithSuiteName('com.apple.MCX')\ .objectForKey('DisableGuestAccount')) let pref2 = ObjC.unwrap($.NSUserDefaults.alloc.initWithSuiteName('com.apple.MCX')\ .objectForKey('EnableGuestAccount')) if ( pref1 == true && pref2 == false ) { return("true") } else { return("false") } } EOS If the result is not "true", this is a finding. |
✔️ Fix |
---|
Configure the macOS system to disable the guest account by installing the "com.apple.MCX" configuration profile. |