3.044 - The computer account password will not be prevented from being reset.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Computer account passwords are changed automatically on a regular basis. Enabling this policy to disable automatic password changes can make the system more vulnerable to malicious access. Frequent password changes can be a significant safeguard for your system. If this policy is disabled, a new password for the computer account will be generated every 30 days.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Domain Member: Disable Machine Account Password Changes' to 'Disabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_R2_MS_V1R33_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CAT|III, CCI|CCI-000366, CSCv6|16, Rule-ID|SV-32308r1_rule, STIG-ID|3.044, Vuln-ID|V-1165

Plugin: Windows

Control ID: 0618181357b5849531db59cbfd1eebe1beb27291796236a1b19504430958b767