2.3.11.6 Ensure 'Network security: Force logoff when logon hours expire' is set to 'Enabled'

Information

This policy setting determines whether to disconnect users who are connected to the local computer outside their user account's valid logon hours.

This setting affects the Server Message Block (SMB) component.

If you enable this policy setting you should also enable _Microsoft network server: Disconnect clients when logon hours expire_ (Rule 2.3.9.4).

The recommended state for this setting is: 'Enabled'.

Note: This recommendation is unscored because there is not a documented registry value that corresponds to it.

We still strongly encourage that it be configured as 'Enabled', to ensure that logon hours (when configured) are properly enforced.

Rationale:

If this setting is disabled, a user could remain connected to the computer outside of their allotted logon hours.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled'.

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Network security: Force logoff when logon hours expire

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/files/1933

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12, CCE|CCE-34993-6, CSCv6|16, CSCv6|16.4

Plugin: Windows

Control ID: ac7fd464570038073986cab1a013c633f03b571adc25dfbd790dcfd7df504a63