1.1.1.2.1.38 Set 'Domain member: Maximum machine account password age' to '30'

Information

This policy setting determines the maximum allowable age for a computer account password. By default, domain members automatically change their domain passwords every 30 days. If you increase this interval significantly or set it to 0 so that the computers no longer change their passwords, an attacker would have more time to undertake a brute force attack against one of the computer accounts. In Active Directorybased domains, each computer has an account and password just like every user. By default, the domain-joined computers automatically change their domain password every 30 days. If you increase this interval significantly, or set it to 0 so that the computers no longer change their passwords, an attacker will have more time to undertake a brute force attack to guess the password of one or more computer accounts.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 30.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Domain member- Maximum machine account password age

Impact- None. This is the default configuration.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CCE|CCE-2984-3

Plugin: Windows

Control ID: f373dea90c68a9da1663ceea9a3f951cc414905e2f6d8870112be39f96284be3