WN12-SO-000016 - The maximum age for machine account passwords must be set to requirements.

Information

Computer account passwords are changed automatically on a regular basis. This setting controls the maximum password age that a machine account may have. This setting must be set to no more than 30 days, ensuring the machine changes its password monthly.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Domain member: Maximum machine account password age' to '30' or less (excluding '0' which is unacceptable).

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-225460r569185_rule, STIG-ID|WN12-SO-000016, STIG-Legacy|SV-52887, STIG-Legacy|V-3373, Vuln-ID|V-225460

Plugin: Windows

Control ID: 7847efa8b80002d909a9f5d1b75d080f6ed34b8d851e17cbb78412e60c55d71c