4.024 - Local users must not exist on a system in a domain.

Information

To minimize potential points of attack, local users, other than built-in accounts such as Administrator and Guest accounts, must not exist on a workstation in a domain. Users must log onto workstations in a domain with their domain accounts.

Solution

Limit local user accounts on domain-joined systems. Remove any unauthorized local accounts.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip