1.56 WN19-AC-000090

Information

Windows Server 2019 reversible password encryption must be disabled.

GROUP ID:V-205653
RULE ID:SV-205653r1051062

Storing passwords using reversible encryption is essentially the same as storing clear-text versions of the passwords, which are easily compromised. For this reason, this policy must never be enabled.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> 'Store passwords using reversible encryption' to 'Disabled'.

See Also

https://workbench.cisecurity.org/benchmarks/22176

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Windows

Control ID: 6b6c27a60d0037f85d4823d44bb19b39f1f6200ff7a9fa1511a2ed348bb4db60