1.202 WN10-SO-000085

Information

Caching of logon credentials must be limited.

GROUP ID: V-220923RULE ID: SV-220923r991589

The default Windows configuration caches the last logon credentials for users who log on interactively to a system. This feature is provided for system availability reasons, such as the user's machine being disconnected from the network or domain controllers being unavailable. Even though the credential cache is well-protected, if a system is attacked, an unauthorized individual may isolate the password to a domain user account using a password-cracking program and gain access to the domain.

Solution

This is the default configuration for this setting (10 logons to cache).

Configure the policy value for

Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)'

to '10' logons or less.

This setting only applies to domain-joined systems, however, it is configured by default on all systems.

See Also

https://workbench.cisecurity.org/benchmarks/23869

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(13)

Plugin: Windows

Control ID: c50edefbe06ea8cb50a14d56b8f75c8a95124382267ef74265464618997ae23b