Kandji is now deprecated. Complete your migration from Kandji to Iru by December 1, 2026 to maintain uninterrupted access. Learn how to migrate

Don't allow the Guest user to log in

Prev Next

By default, macOS allows a Guest user account that grants access to the general macOS system and apps without login credentials. The Guest user is considered a security vulnerability because it does not have a password.

It is recommended that the Guest user account be disabled on all macOS systems unless there is a demonstrated need.

Enabling this Parameter

When enabled, Kandji will ensure the Guest user feature is disabled. During each check-in, Kandji will verify and adjust settings to the disabled state should they change.

Disabling this Parameter

Disabling this parameter stops Kandji from disabling the Guest user feature during each check-in. The feature will remain disabled until a user enables the Guest user again.

For more detailed information on Parameters, see the Parameters section of our Knowledge Base.