STIGQter STIGQter: STIG Summary: Apple macOS 15 (Sequoia) Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Apr 2026:

The macOS system must disable accounts after 35 days of inactivity.

DISA Rule

SV-268549r1131246_rule

Vulnerability Number

V-268549

Group Title

SRG-OS-000118-GPOS-00060

Rule Version

APPL-15-003080

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the macOS system to disable accounts after 35 days of inactivity with the following command:

This setting may be enforced using local policy.

To set local policy to disable an inactive user after 35 days, edit the current password policy to contain the following <dict> within the "policyCategoryAuthentication":

[source,xml]
----
<dict>
<key>policyContent</key>
<string>policyAttributeLastAuthenticationTime &gt; policyAttributeCurrentTime - (policyAttributeInactiveDays * 24 * 60 * 60)</string>
<key>policyIdentifier</key>
<string>Inactive Account</string>
<key>policyParameters</key>
<dict>
<key>policyAttributeInactiveDays</key>
<integer>35</integer>
</dict>
</dict>
----
After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file".

[source,bash]
----
/usr/bin/pwpolicy setaccountpolicies $pwpolicy_file
----

Check Contents

Verify the macOS system is configured to disable accounts after 35 days of inactivity with the following command:

/usr/bin/pwpolicy -getaccountpolicies 2> /dev/null | /usr/bin/tail +2 | /usr/bin/xmllint --xpath '//dict/key[text()="policyAttributeInactiveDays"]/following-sibling::integer[1]/text()' -

If the result is not "35", this is a finding.

Vulnerability Number

V-268549

Documentable

False

Rule Version

APPL-15-003080

Severity Override Guidance

Verify the macOS system is configured to disable accounts after 35 days of inactivity with the following command:

/usr/bin/pwpolicy -getaccountpolicies 2> /dev/null | /usr/bin/tail +2 | /usr/bin/xmllint --xpath '//dict/key[text()="policyAttributeInactiveDays"]/following-sibling::integer[1]/text()' -

If the result is not "35", this is a finding.

Check Content Reference

M

Target Key

5661