Network security: Force logoff when logon hours expire

Information

Network security: Force logoff when logon hours expire

This security setting determines whether to disconnect users who are connected to the local computer outside their user account's valid logon hours. This setting affects the Server Message Block (SMB) component.

When this policy is enabled, it causes client sessions with the SMB server to be forcibly disconnected when the client's logon hours expire.

If this policy is disabled, an established client session is allowed to be maintained after the client's logon hours have expired.

Default: Enabled.

Note: This security setting behaves as an account policy. For domain accounts, there can be only one account policy. The account policy must be defined in the Default Domain Policy, and it is enforced by the domain controllers that make up the domain. A domain controller always pulls the account policy from the Default Domain Policy Group Policy object (GPO), even if there is a different account policy applied to the organizational unit that contains the domain controller. By default, workstations and servers that are joined to a domain (for example, member computers) also receive the same account policy for their local accounts. However, local account policies for member computers can be different from the domain account policy by defining an account policy for the organizational unit that contains the member computers. Kerberos settings are not applied to member computers.

Solution

Policy Path: Local Policies\Security Options
Policy Name: Network security: Force logoff when logon hours expire

See Also

https://www.microsoft.com/en-us/download/details.aspx?id=55319

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12, CSCv6|16, CSCv6|16.4

Plugin: Windows

Control ID: 26e3a19f6e4620c9c63e1ade9175a737d1727c7358ee79808eb5c452f54af250