WN12-SO-000025 - Users must be warned in advance of their passwords expiring.

Information

Creating strong passwords that can be remembered by users requires some thought. By giving the user advance warning, the user has time to construct a sufficiently strong password. This setting configures the system to display a warning to users telling them how many days are left before their password expires.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Interactive Logon: Prompt user to change password before expiration' to '14' days or more.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_DC_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-226291r794589_rule, STIG-ID|WN12-SO-000025, STIG-Legacy|SV-52876, STIG-Legacy|V-1172, Vuln-ID|V-226291

Plugin: Windows

Control ID: 534d4efe0761f26a4ee6c3791b071e0b9119a102e78d1c581f5f765ec5c12f30