Information
Windows notices inactivity of a logon session, and if the amount of inactive time exceeds the inactivity limit, then the screen saver will run, locking the session.
The recommended state for this setting is: 15 or fewer minutes, but not 0
Note: A value of 0 does not conform to the benchmark as it disables the machine inactivity limit.
If a user forgets to lock their computer when they walk away it's possible that a passerby will hijack it.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to 15 or fewer minutes, but not 0 :
Device Lock\Device Password Enabled: Max Inactivity Time Device Lock
Impact:
The screen saver will automatically activate when the computer has been unattended for the amount of time specified. The impact should be minimal since the screen saver is enabled by default.