1.1.3 Ensure 'Minimum password age' is set to '1 or more day(s)'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting determines the number of days that you must use a password before you can change it.

The range of values for this policy setting is between 1 and 999 days.

(You may also set the value to 0 to allow immediate password changes.) The default value for this setting is 0 days.

The recommended state for this setting is: '1 or more day(s)'.

Solution

To establish the recommended configuration via GP, set the following UI path to '1 or more day(s)':

Computer Configuration\Policies\Windows Settings\Security Settings\Account Policies\Password Policy\Minimum password age

See Also

https://workbench.cisecurity.org/files/1941

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv6|16.5

Plugin: Windows

Control ID: 8055dbb3a599c95240ea6f16eaf2d9f0f46ef9dd1ffe5fc0c93d6d39dce3e08f