1. Home
  2. Security Hardening
  3. CIS Microsoft Windows 10 Enterprise Release 21H1 V1.11.0 L2 Bl
  4. Ensure ‘MSS: (DisableSavePassword) Prevent the dial-up password from being saved’ is set to ‘Enabled’

Ensure ‘MSS: (DisableSavePassword) Prevent the dial-up password from being saved’ is set to ‘Enabled’

Details

When you dial a phonebook or VPN entry in Dial-Up Networking, you can use the ‘Save Password’ option so that your Dial-Up Networking password is cached and you will not need to enter it on successive dial attempts. For security, administrators may want to prevent users from caching passwords.

The recommended state for this setting is: Enabled.

Rationale:

An attacker who steals a mobile user’s computer could automatically connect to the organization’s network if the Save This Password check box is selected for the dial-up or VPN networking entry used to connect to your organization’s network.

Impact:

Users will not be able to automatically store their logon credentials for dial-up and VPN connections.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

Computer ConfigurationPoliciesAdministrative TemplatesMSS (Legacy)MSS:(DisableSavePassword) Prevent the dial-up password from being saved

Note: This Group Policy path does not exist by default. An additional Group Policy template (MSS-legacy.admx/adml) is required – it is available from this TechNet blog post: The MSS settings – Microsoft Security Guidance blog

Default Value:

Disabled. (Saving of dial-up and VPN passwords is allowed.)

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles