Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to make use of system accounts.
Check
Verify that RHEL 9 system accounts do not have an interactive login shell.
Run the following command to list any system account (UID < 1000) that has an interactive shell, excluding authorized system utility accounts (root, sync, shutdown, halt):