4.043 - The maximum age for machine account passwords is not set to requirements.

Information

This setting controls the maximum password age that a machine account may have. This setting should be set to no more than 30 days, ensuring the machine changes its password monthly.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Domain Member- Maximum Machine Account Password Age' to 30 or less, but not 0.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-29246r1_rule, STIG-ID|4.043, Vuln-ID|V-3373

Plugin: Windows

Control ID: c562d340373951ecc87e83bf9ab33001f08b303ab36b62085ab0910495f5425e