1.140 WN10-CC-000200

Information

Administrator accounts must not be enumerated during elevation.

GROUP ID: V-220832RULE ID: SV-220832r958518

Enumeration of administrator accounts when elevating can provide part of the logon information to an unauthorized user. This setting configures the system to always require users to type in a username and password to elevate a running application.

Solution

Configure the policy value for

Computer Configuration >> Administrative Templates >> Windows Components >> Credential User Interface >> 'Enumerate administrator accounts on elevation'

to 'Disabled'.

See Also

https://workbench.cisecurity.org/benchmarks/23869

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-3, CCI|CCI-001084, Rule-ID|SV-220832r958518_rule, STIG-ID|WN10-CC-000200, Vuln-ID|V-220832

Plugin: Windows

Control ID: 56599253cd4d84e587562829f82f4915d1d67cc5851e12b10e3758dcc776e46c