18.9.15.2 (L1) Ensure 'Enumerate administrator accounts on elevation' is set to 'Disabled'

Information

This policy setting controls whether administrator accounts are displayed when a user attempts to elevate a running application.
The recommended state for this setting is: Disabled.

Rationale:
Users could see the list of administrator accounts, making it slightly easier for a malicious user who has logged onto a console session to try to crack the passwords of those accounts.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:
Computer Configuration\Policies\Administrative Templates\Windows Components\Credential User Interface\Enumerate administrator accounts on elevation
Note: This Group Policy path is provided by the Group Policy template CredUI.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:
None - this is the default behavior.

Default Value:
Disabled. (Users will be required to always type in a username and password to elevate.)

References:
1. CCE-35194-0

See Also

https://workbench.cisecurity.org/benchmarks/14249

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1), CSCv6|16, CSCv7|4.5

Plugin: Windows

Control ID: a9d9bccbb2a26e6828405130ef9a82682601656ecccbc962be8c8260af68449c