The macOS system must enable Authenticated Root.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-268565SRG-OS-000080-GPOS-00048APPL-15-005070SV-268565r1034635_rule2025-02-201
Description
Authenticated Root must be enabled. When Authenticated Root is enabled, the macOS is booted from a signed volume that is cryptographically protected to prevent tampering with the system volume. NOTE: Authenticated Root is enabled by default on macOS systems. WARNING: If more than one partition with macOS is detected, the csrutil command will hang awaiting input.
ℹ️ Check
Verify the macOS system is configured to enable authenticated root with the following command: /usr/libexec/mdmclient QuerySecurityInfo | /usr/bin/grep -c "AuthenticatedRootVolumeEnabled = 1;" If the result is not "1", this is a finding.
✔️ Fix
Configure the macOS system to enable authenticated root with the following command: /usr/bin/csrutil authenticated-root enable NOTE: To reenable "Authenticated Root", boot the affected system into "Recovery" mode, launch "Terminal" from the "Utilities" menu, and run the command.