Information
Standard local user accounts must not exist on a system in a domain.
GROUP ID: V-220715RULE ID: SV-220715r991589
To minimize potential points of attack, local user accounts, other than built-in accounts and local administrator accounts, must not exist on a workstation in a domain. Users must log on to workstations in a domain with their domain accounts.
Solution
Limit local user accounts on domain-joined systems. Remove any unauthorized local accounts.