I type sudo several times a day, and my Mac has a fingerprint reader right next to the keyboard. For years, getting sudo to use it meant editing /etc/pam.d/sudo, and every macOS update quietly put the file back. I re-applied the same edit after every single update.
Short version: since macOS Sonoma, /etc/pam.d/sudo includes a file called sudo_local that updates leave alone. Copy it from the template Apple ships, uncomment the pam_tid.so line, and sudo asks for your fingerprint.
How the local file works
sudo authenticates through PAM, a stack of modules listed in /etc/pam.d/sudo. That file is owned by the system, so updates overwrite it. On Sonoma, its first line pulls in sudo_local, which only exists if you create it. Apple ships sudo_local.template next to it as the starting point.
The module that talks to Touch ID is pam_tid.so. It’s marked sufficient, so a fingerprint is enough on its own, and if Touch ID isn’t available or you cancel the prompt, PAM moves on to the password as before.
Enable Touch ID for sudo
Check that the template is there:
$ cd /etc/pam.d$ ls -l sudo*.r--r--r-- 283 root 16 Sep 15:28 sudo.r--r--r-- 179 root 16 Sep 15:28 sudo_local.templateCopy it and open the copy. The -n keeps an existing sudo_local, in case you’ve set one up before:
sudo cp -n sudo_local.template sudo_localsudo -e sudo_localUncomment the pam_tid.so line so the file reads:
# sudo_local: local config file which survives system update and is included for sudo# uncomment following line to enable Touch ID for sudoauth sufficient pam_tid.soOpen a new terminal and run any sudo command. You get the Touch ID prompt instead of the password prompt.
Where it doesn’t work
The prompt needs the GUI session, so it falls back to the password in a few places: over SSH, with the lid closed and no external Touch ID keyboard, and inside tmux. I use tmux, so the last one is the one I needed fixed.
pam_reattach fixes it by moving sudo back into your GUI session before pam_tid.so runs. Install it with Homebrew:
brew install pam-reattachThen add it above the Touch ID line, as the pam_reattach README describes. On Apple silicon, Homebrew installs into /opt/homebrew, where PAM doesn’t look, so the module needs its full path. On an Intel Mac it lands in /usr/local/lib/pam, and plain pam_reattach.so is enough. brew --prefix tells you which one you have.
# sudo_local: local config file which survives system update and is included for sudoauth optional /opt/homebrew/lib/pam/pam_reattach.so ignore_sshauth sufficient pam_tid.soignore_ssh keeps it from offering Touch ID in a tmux session you attached to over SSH, where nobody is sitting at the fingerprint reader.
To undo it, comment out the pam_tid.so line again, or delete sudo_local.
References
- What’s new for enterprise in macOS Sonomasupport.apple.comthe release note that introduced sudo_local
- pam_reattachgithub.commakes Touch ID work inside tmux