Accounts must be configured to require password expiration.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-220716SRG-OS-000076-GPOS-00044WN10-00-000090SV-220716r1051019_rule2025-02-253
Description
Passwords that do not expire increase exposure with a greater probability of being discovered or cracked.
ℹ️ Check
Run "Computer Management". Navigate to System Tools >> Local Users and Groups >> Users. Double-click each active account. If "Password never expires" is selected for any account, this is a finding.
✔️ Fix
Configure all passwords to expire. Run "Computer Management". Navigate to System Tools >> Local Users and Groups >> Users. Double-click each active account. Ensure "Password never expires" is not checked on all active accounts.