2.3.11.6 Ensure 'Network security: Force logoff when logon hours expire' is set to 'Enabled'

Information

This policy setting determines whether to disconnect users who are connected to the local computer outside their user account's valid logon hours. This setting affects the Server Message Block (SMB) component. If you enable this policy setting you should also enable Microsoft network server: Disconnect clients when logon hours expire (Rule 2.3.9.4).

The recommended state for this setting is: Enabled.

Note: Certain policy settings must be configured in the Default Domain Policy to ensure they are applied globally. Exercise caution when modifying these policies, as improper changes can negatively impact the environment.

Only policies that are configured by Microsoft by default should reside in these baseline GPOs. Any additional or custom policy settings should be implemented through separate GPOs rather than modifying the default policies.

If this setting is disabled, a user could remain connected to the computer outside of their allotted logon hours.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled.

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Network security: Force logoff when logon hours expire

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/27461