1.1.1 Ensure 'Enforce password history' is set to '24 or more password(s)'

Information

This policy setting determines the number of renewed, unique passwords that have to be associated with a user account before you can reuse an old password.

The value for this policy setting must be between 0 and 24 passwords.

The default value for Windows Vista is 0 passwords, but the default setting in a domain is 24 passwords.

To maintain the effectiveness of this policy setting, use the Minimum password age setting to prevent users from repeatedly changing their password.

The recommended state for this setting is: '24 or more password(s)'.

Solution

To establish the recommended configuration via GP, set the following UI path to '24 or more password(s)':

Computer Configuration\Policies\Windows Settings\Security Settings\Account Policies\Password Policy\Enforce password history

See Also

https://workbench.cisecurity.org/files/1941

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv6|16.5

Plugin: Windows

Control ID: d03eb2d9a0b994d9292bc188479a5203f568a67af3555184fb5f7d91135cdfae