STIGQter STIGQter: STIG Summary: Apple macOS 15 (Sequoia) Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Apr 2026:

The macOS system must allow smart card authentication.

DISA Rule

SV-268543r1034569_rule

Vulnerability Number

V-268543

Group Title

SRG-OS-000068-GPOS-00036

Rule Version

APPL-15-003030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the macOS system to enforce multifactor authentication by installing the "com.apple.security.smartcard" configuration profile.

NOTE: To ensure continued access to the operating system, consult the supplemental guidance provided with the STIG before applying the configuration profile.

Check Contents

Verify the macOS system is configured to allow smart card authentication with the following command:

/usr/bin/osascript -l JavaScript << EOS
$.NSUserDefaults.alloc.initWithSuiteName('com.apple.security.smartcard')\
.objectForKey('allowSmartCard').js
EOS

If the result is not "true", this is a finding.

Vulnerability Number

V-268543

Documentable

False

Rule Version

APPL-15-003030

Severity Override Guidance

Verify the macOS system is configured to allow smart card authentication with the following command:

/usr/bin/osascript -l JavaScript << EOS
$.NSUserDefaults.alloc.initWithSuiteName('com.apple.security.smartcard')\
.objectForKey('allowSmartCard').js
EOS

If the result is not "true", this is a finding.

Check Content Reference

M

Target Key

5661