3.070 - The system will be configured to prevent the storage of passwords and credentials

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This setting controls the storage of passwords and credentials for network authentication on the local system. Such credentials should never be stored on the local machine as that may lead to account compromise.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Network access: Do not allow storage of passwords and credentials for network authentication' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_R2_DC_V1R34_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CAT|II, CCI|CCI-002038, CSCv6|16.13, CSCv6|16.14, Rule-ID|SV-32336r1_rule, STIG-ID|3.070, Vuln-ID|V-3376

Plugin: Windows

Control ID: 1f80ae7201ff17a4d7b4f0a2db9f06628a0558705e8d0696dd80c7d18ec8765e