Smart Card + User Switching

user-aQddpcOjVL
New Contributor

Scenario: we have a mac at our reception desk that multiple people need to use throughout the day. I have enabled smart card only authentication and created local user accounts, and allocated a Yubikey 5 to each user that needs to use the mac.

Signing in from the login screen works great - the user is recognised when they insert their Yubikey and they can quickly sign in with their PIN. I have configured the mac through a profile to lock the screen when the Yubikey is removed.

The part that is not yet working as well as I'd like is the user switching. If one user removes their Yubikey, the lock screen is shown, as expected. When a different user inserts their Yubikey, the lock screen does not recognise this new user - the only way that happens is for the user to click "switch user" on the lock screen. The login screen then dutifully recognises this new user.

So I guess I'm trying to show the login screen when each user removes their Yubikey, rather than the lock screen. How can I force this to happen? It's not the end of the world for the new user to click "switch user" but it sure is a better UX for the new user to be recognised when they insert their key!

3 REPLIES 3

boberito
Valued Contributor

You can't. That's how the operating system works.

user-aQddpcOjVL
New Contributor

That's somewhat surprising given how widely used smart card authentication is and how much nicer the UX is if you don't have to click "switch user" on the lock screen. I don't see how this functionality would compromise security when a user can initiate it with a button click and a PIN is required to sign in...

JustDeWon
Contributor III

@user-aQddpcOjVL , I'm not sure I understand the surprise, cause even without SmartCards, the default action of the OS is if someone is logged-in, and the screen locks, in order for a different user to login, you have to switch-users... Or you can log out of the profile.

If you want a better UX, just enable "Fast User Switching", which will allow switching of users while currently logged-in. Pretty much the only 3 choices provided to you by Apple