Accounts must be configured to require password expiration.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
medium | V-220716 | SRG-OS-000076-GPOS-00044 | WN10-00-000090 | SV-220716r1051019_rule | 2025-02-25 | 3 |
Description |
---|
Passwords that do not expire increase exposure with a greater probability of being discovered or cracked. |
ℹ️ Check |
---|
Run "Computer Management". Navigate to System Tools >> Local Users and Groups >> Users. Double-click each active account. If "Password never expires" is selected for any account, this is a finding. |
✔️ Fix |
---|
Configure all passwords to expire. Run "Computer Management". Navigate to System Tools >> Local Users and Groups >> Users. Double-click each active account. Ensure "Password never expires" is not checked on all active accounts. |