1.1.1.1.1.3 Configure 'Maximum lifetime for user ticket'

Information

This security setting determines the maximum amount of time (in hours) that a user's ticket-granting ticket (TGT) may be used. When a user's TGT expires, a new one must be requested or the existing one must be renewed. Default: 10 hours. If you configure the value for the Maximum lifetime for user ticket setting too high, then users might be able to access network resources outside of their logon hours. Also, users whose accounts were disabled might continue to have access to network services with valid service tickets that were issued before their accounts were disabled.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy\Maximum lifetime for user ticket

Impact- Reducing this setting from the default value reduces the likelihood that the TGT will be used to access resources that the user does not have rights to. However, it will require more frequent requests to the KDC for TGTs on behalf of users. Most KDCs can support a value of four hours without too much additional burden.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(13), CCE|CCE-3625-1

Plugin: Windows

Control ID: b40d4f9b6dc974196d90ac2bf5d0b88e9cf574313cee557bfc2ac14f4ef1faeb