1.3.3 Ensure 'Maximum lifetime for user ticket' is set to '10 or fewer hours, but not 0' (STIG DC only)

Information

This security setting determines the maximum amount of time (in hours) that a user's ticket-granting ticket (TGT) may be used.

The STIG recommended state for this setting is: 10 or fewer hours, but not 0

If you configure the value for the Maximum lifetime for user ticket setting too high, users might be able to access network resources outside of their logon hours. Also, users whose accounts were disabled might continue to have access to network services with valid user tickets that were issued before their accounts were disabled. If you configure this value too low, ticket requests to the KDC may affect the performance of your KDC and present an opportunity for a DoS attack.

Solution

To establish the recommended configuration via GP, set the following UI path to 10 or fewer hours, but not 0 :

Computer Configuration\Policies\Windows Settings\Security Settings\Account Policy\Kerberos Policy\Maximum lifetime for user ticket

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/18857

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(13)

Plugin: Windows

Control ID: 3c7cef0ea632191357d85e05c8da6456d699a25af54460ddb067c04b7e27861e