STIGQter STIGQter: STIG Summary: Apple macOS 15 (Sequoia) Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Apr 2026:

The macOS system must limit consecutive failed login attempts to three.

DISA Rule

SV-268428r1131182_rule

Vulnerability Number

V-268428

Group Title

SRG-OS-000021-GPOS-00005

Rule Version

APPL-15-000022

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the macOS system to limit consecutive failed login attempts to three by installing the "com.apple.mobiledevice.passwordpolicy" configuration profile.

Check Contents

Verify the macOS system is configured to limit consecutive failed login attempts to three with the following command:

/usr/bin/pwpolicy -getaccountpolicies 2> /dev/null | /usr/bin/tail +2 | /usr/bin/xmllint --xpath '//dict/key[text()="policyAttributeMaximumFailedAuthentications"]/following-sibling::integer[1]/text()' - | /usr/bin/awk '{ if ($1 <= 3) {print "yes"} else {print "no"}}' | /usr/bin/uniq

If the result is not "yes", this is a finding.

Vulnerability Number

V-268428

Documentable

False

Rule Version

APPL-15-000022

Severity Override Guidance

Verify the macOS system is configured to limit consecutive failed login attempts to three with the following command:

/usr/bin/pwpolicy -getaccountpolicies 2> /dev/null | /usr/bin/tail +2 | /usr/bin/xmllint --xpath '//dict/key[text()="policyAttributeMaximumFailedAuthentications"]/following-sibling::integer[1]/text()' - | /usr/bin/awk '{ if ($1 <= 3) {print "yes"} else {print "no"}}' | /usr/bin/uniq

If the result is not "yes", this is a finding.

Check Content Reference

M

Target Key

5661