1.219 WN22-SO-000120

Information

Windows Server 2022 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.

GROUP ID: V-254456
RULE ID: SV-254456r958400

Unattended systems are susceptible to unauthorized use and must be locked when unattended. The screen saver must be set at a maximum of 15 minutes and be password protected. This protects critical and sensitive data from exposure to unauthorized personnel with physical access to the computer.

Satisfies: SRG-OS-000028-GPOS-00009, SRG-OS-000029-GPOS-00010, SRG-OS-000031-GPOS-00012

Solution

Configure the policy value for

Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Interactive logon: Machine inactivity limit to '900' seconds or less, excluding '0' which is effectively disabled

See Also

https://workbench.cisecurity.org/benchmarks/22357

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11(1), 800-53|AC-11a., 800-53|AC-11b., CAT|II, CCI|CCI-000056, CCI|CCI-000057, CCI|CCI-000060, Rule-ID|SV-254456r958400_rule, STIG-ID|WN22-SO-000120, Vuln-ID|V-254456

Plugin: Windows

Control ID: 0de3685329faaa2cd9f747f72d7d8593026714fea85c1895fef81fb6569b41fb