WN12-PK-000008-DC - Active directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), PIV-compliant hardware token, or Alternate Logon Token (ALT) for user authentication.

Information

Smart cards such as the Common Access Card (CAC) support a two-factor authentication technique. This provides a higher level of trust in the asserted identity than use of the username and password for authentication.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure all user accounts, including administrator accounts, in Active Directory to enable the option 'Smart card is required for interactive logon'.

Run 'Active Directory Users and Computers' (Available from various menus or run 'dsa.msc'):
Select the Organizational Unit (OU) where the user accounts are located. (By default this is the Users node; however, accounts may be under other organization-defined OUs.)
Right click the user account and select 'Properties'.
Select the 'Account' tab.
Check 'Smart card is required for interactive logon' in the 'Account Options' area.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_DC_V3R7_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1), 800-53|IA-2(2), 800-53|IA-2(3), 800-53|IA-2(4), 800-53|IA-2(11), CAT|II, CCI|CCI-000765, CCI|CCI-000766, CCI|CCI-000767, CCI|CCI-000768, CCI|CCI-001948, Rule-ID|SV-226267r852130_rule, STIG-ID|WN12-PK-000008-DC, STIG-Legacy|SV-51192, STIG-Legacy|V-15488, Vuln-ID|V-226267

Plugin: Windows

Control ID: 6689c8f8db0857d95060e1255d6591eb043cf4463dc1e779e53d180a29ff2bf2