2.3.9.4 Ensure 'Microsoft network server: Disconnect clients when logon hours expire' is set to 'Enabled'

Information

This security setting determines whether to disconnect users who are connected to the local computer outside their user account's valid logon hours.

This setting affects the Server Message Block (SMB) component.

If you enable this policy setting you should also enable Network security: Force logoff when logon hours expire (Rule 2.3.11.6).

If your organization configures logon hours for users, this policy setting is necessary to ensure they are effective.

The recommended state for this setting is: 'Enabled'.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled':

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Microsoft network server: Disconnect clients when logon hours expire

See Also

https://workbench.cisecurity.org/files/1941