Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Sensamic

macrumors 68040
Original poster
Trying out my girlfriends iMac M1 with Magic Keyboard and TouchID I just check that I can't use my fingerprint to log in after initial boot. Is that so for everyone? Or is there a setting I have to find?
 
You need to log in once using a password to unlock the drive (filevault) and the area (secure enclave) that stores fingerprints.

 
  • Like
Reactions: Sensamic
Yeah it’s a fundamental part of the security architecture. The fingerprint reader in the keyboard and the Secure Enclave have no session key to unlock with on first boot. Fingerprint is not considered a master key on the system only the password is. So after you enter the password the Secure Enclave generates a session key that the fingerprint reader can unlock with.
It can be invalidated with a timeout or find my marking the device as lost and such to reduce the threat vector
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.