1.1.1.2.1.13 Set 'MSS: (DisableSavePassword) Prevent the dial-up password from being saved (recommended)' to 'Enabled'

Information

This entry appears as MSS: (DisableSavePassword) Prevent the dial-up password from being saved (recommended) in the SCE. By default, Windows will offer the option to save passwords for dial-up and VPN connections, which is not desirable on a server. You can add this registry value to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\ Parameters\ subkey. An attacker who steals a mobile user's computer could automatically connect to the organization's network if the Save This Password check box is enabled for the dial-up entry.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 1.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\MSS- (DisableSavePassword) Prevent the dial-up password from being saved (recommended)

Impact- Users won't be able to automatically store their logon credentials for dial-up and VPN connections.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CCE|CCE-3757-2

Plugin: Windows

Control ID: aa2f1ec2b576e2436d0e038909135df7602df3b6e1728ff449fe9565c80d86dd