85.6 (L1) Ensure 'Post Authentication Reset Delay' is set to 'Configured: 8 or fewer hours, but not 0'

Information

This policy settings configures post-authentication actions which will be executed after detecting an authentication by the Windows LAPS managed account. The Grace period refers to the amount of time (hours) to wait after an authentication before executing the specified post-authentication actions.

The recommended state for this setting is: Configured: 8 or fewer hours, but not 0

Note: Organizations that utilize third-party commercial software to manage unique & complex local Administrator passwords on domain members may opt to disregard these LAPS recommendations.

Note #2: Windows LAPS does not support standalone computers - they must be joined to an Active Directory domain or Entra ID (formerly Azure Active Directory).

Note #3: If this policy is set to 0 it prevents all post-authentication actions from occurring.

Due to the difficulty in managing local Administrator passwords, many organizations choose to use the same password on all workstations and/or Member Servers when deploying them. This creates a serious attack surface security risk because if an attacker manages to compromise one system and learn the password to its local Administrator account, then they can leverage that account to instantly gain access to all other computers that also use that password for their local Administrator account.

Solution

To establish the recommended configuration from Microsoft Intune Admin Center:

- Navigate to Endpoint security > Account protection
- Create or edit a LAPS policy type Local admin password solution (Windows LAPS)
- Set Post Authentication Reset Delay to Configured: 8 (or fewer hours, but not 0)

Impact:

After 8 hours, the Windows LAPS managed account password will be reset and log off the system.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)

Plugin: Windows

Control ID: ae4fc98cca6aa527042958ac8217e603400582a9c0477335bbac04738bb42a1f