1. Home
  2. Security Hardening
  3. DISA Windows 10 STIG V2R3
  4. WN10-00-000090 – Accounts must be configured to require password expiration.

WN10-00-000090 – Accounts must be configured to require password expiration.

Details

Passwords that do not expire increase exposure with a greater probability of being discovered or cracked.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure all passwords to expire.
Run ‘Computer Management’.
Navigate to System Tools >> Local Users and Groups >> Users.
Double click each active account.
Ensure ‘Password never expires’ is not checked on all active accounts.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles