So were going through some testing on our macs and discovered that an individual (who doesn't have admin rights) can go into single user mode and esclate their permissions to admin. So the simple question is how do we disable a user from being able to go into single user mode.
Searching on the web it referred to a /etc/rc.boot file. I don't see that file in our current build (10.10.1 and 10.10.3). I do see rc.comm, rc.imagin, and rc.netboot. So which one should I edit to disable single user mode, and more specifically - how. Is this the right file to edit, or is there another file?
I'd like to avoid using a firmware password if possible at first to make life easier for users. What are you guys out there doing?
