Posted on 04-06-2021 05:47 AM
Scenario: we have a mac at our reception desk that multiple people need to use throughout the day. I have enabled smart card only authentication and created local user accounts, and allocated a Yubikey 5 to each user that needs to use the mac.
Signing in from the login screen works great - the user is recognised when they insert their Yubikey and they can quickly sign in with their PIN. I have configured the mac through a profile to lock the screen when the Yubikey is removed.
The part that is not yet working as well as I'd like is the user switching. If one user removes their Yubikey, the lock screen is shown, as expected. When a different user inserts their Yubikey, the lock screen does not recognise this new user - the only way that happens is for the user to click "switch user" on the lock screen. The login screen then dutifully recognises this new user.
So I guess I'm trying to show the login screen when each user removes their Yubikey, rather than the lock screen. How can I force this to happen? It's not the end of the world for the new user to click "switch user" but it sure is a better UX for the new user to be recognised when they insert their key!
Posted on 04-06-2021 06:11 AM
You can't. That's how the operating system works.
Posted on 04-11-2021 05:42 PM
That's somewhat surprising given how widely used smart card authentication is and how much nicer the UX is if you don't have to click "switch user" on the lock screen. I don't see how this functionality would compromise security when a user can initiate it with a button click and a PIN is required to sign in...
Posted on 04-12-2021 10:14 AM
@user-aQddpcOjVL , I'm not sure I understand the surprise, cause even without SmartCards, the default action of the OS is if someone is logged-in, and the screen locks, in order for a different user to login, you have to switch-users... Or you can log out of the profile.
If you want a better UX, just enable "Fast User Switching", which will allow switching of users while currently logged-in. Pretty much the only 3 choices provided to you by Apple