18.10.14.3 (L1) Ensure 'Prevent the use of security questions for local accounts' is set to 'Enabled'

Information

This policy setting controls whether security questions can be used to reset local account passwords. The security question feature does not apply to domain accounts, only local accounts on the workstation.

The recommended state for this setting is: Enabled

Users could establish security questions that are easily guessed or sleuthed by observing the user's social media accounts, making it easier for a malicious actor to change the local user account password and gain access to the computer as that user account.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Credential User Interface\Prevent the use of security questions for local accounts

Note: This Group Policy path is provided by the Group Policy template CredUI.admx/adml that is included with the Microsoft Windows 10 Release 1903 Administrative Templates (or newer).

Impact:

Local user accounts will not be able to set up and use security questions to reset their passwords.

See Also

https://workbench.cisecurity.org/benchmarks/16514

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 7666843bc964e2b39ca76ee547c32cc8cdef839ec80eaeeff7379a5df4c51159