WN12-GE-000015 - Windows 2012/2012 R2 accounts must be configured to require passwords.

Information

The lack of password protection enables anyone to gain access to the information system, which opens a backdoor opportunity for intruders to compromise the system as well as other resources. Accounts on a system must require passwords.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure all enabled accounts to require passwords.

The password required flag can be set by entering the following on a command line: 'Net user [username] /passwordreq:yes', substituting [username] with the name of the user account.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, CAT|I, CCI|CCI-000764, Rule-ID|SV-225426r569185_rule, STIG-ID|WN12-GE-000015, STIG-Legacy|SV-52940, STIG-Legacy|V-7002, Vuln-ID|V-225426

Plugin: Windows

Control ID: 48bee03300a2d250a225ff06041baae0bb9af79bf41d8339a4ede11fd203a336