SHPT-00-000600 - SharePoint managed service accounts must be set to enable automatic password change.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Passwords have a number of inherent risks. One method of minimizing this risk is to enforce the use of complex passwords. Another method is to enforce periodic password changes. If the information system does not limit the lifetime of passwords and force password changes, the system may be vulnerable to password attacks and may become compromised.

This setting only enables automatic password changes for managed account. These accounts are in AD DS. The Windows server STIG guidance requires annual password changes for all service accounts.

Solution

1. In SharePoint Central Administration, click Security.
2. On the Security page, in the General Security list, click Configure managed accounts.
3. Edit setting for each managed account.
4. Select Enable automatic password change.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2015/U_Sharepoint_2010_V1R7_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CAT|II, CCI|CCI-000199, Rule-ID|SV-37784r2_rule, STIG-ID|SHPT-00-000600, Vuln-ID|V-28138

Plugin: Windows

Control ID: 9a238c0399b249f405c660d472d41d64a9d7e05ec8ea001f3c66925f42e8aa24