18.9.39.2 (L1) Ensure 'Configure SAM change password RPC methods policy' is set to 'Enabled: Allow strong encryption change password RPC method only' (DC only)

Information

This policy setting determines which RPC methods can be used to change passwords stored in the Security Account Manager (SAM).

The recommended state for this setting is: Enabled: Allow strong encryption change password RPC method only

User passwords stored in the SAM should only be changed from a Domain Controller using secure methods.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Allow strong encryption change password RPC method only :

Computer Configuration\Policies\Administrative Templates\System\Security Account Manager\Configure SAM change password RPC methods policy

Note: This Group Policy path is provided by the Group Policy template SAM.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/21344

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Windows

Control ID: 62781f1dc662c0cb3e2ea1ebd79522a8ba22f82297db263b6deda195b512c8bc