1.1.1.1.1.2 Configure 'Enforce user logon restrictions'

Information

Kerberos policy settings determine Kerberos-related attributes of domain user accounts, such as the Maximum lifetime for user ticket and Enforce user logon restrictions settings. However, these policy settings are not used for stand-alone client computers because they do not participate in a domain. If you disable this policy setting, users could receive session tickets for services that they no longer have the right to use because the right was removed after they logged on.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy\Enforce user logon restrictions

Impact- None. This is the default configuration.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(11), CCE|CCE-3700-2

Plugin: Windows

Control ID: a68b9378b3a42db5b8b219e7b9174994fb6d163a9e21e9e83d9381cbf7242d70