1.216 WN22-SO-000090

Information

Windows Server 2022 computer account password must not be prevented from being reset.

GROUP ID: V-254453
RULE ID: SV-254453r971545

Computer account passwords are changed automatically on a regular basis. Disabling automatic password changes can make the system more vulnerable to malicious access. Frequent password changes can be a significant safeguard for the system. A new password for the computer account will be generated every 30 days.

Solution

Configure the policy value for

Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain member: Disable machine account password changes to 'Disabled'

See Also

https://workbench.cisecurity.org/benchmarks/22357

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5g.

Plugin: Windows

Control ID: de062a2630d4ad65bd5b69ff88a6598c8654ba9f97c5f1be3decd602a7d4e951