Information
This policy setting determines whether users can use private keys, such as their Secure/Multipurpose Internet Mail Extensions (S/MIME) key, without a password.
The STIG recommended state for this setting is: User must enter a password each time they use a key
If a private key is compromised, an attacker can use the keys that are stored to gain access to the network. If users must provide a password each time they use the key, it will make it more difficult for an attacker to access locally stored keys.
Solution
To establish the recommended configuration via GP, set the following UI path to User must enter a password each time they use a key :
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\System Cryptography: Force strong key protection for user keys stored on the computer
Impact:
A user must provide a password each time they use a key. This is in addition to their domain password.