5.047 - Terminal Services idle session time limit does not meet the requirement.

Information

This setting controls how long a session may be idle before it is automatically disconnected from the server. Users should disconnect if they plan on being away from their terminals for extended periods of time. Idle sessions should be disconnected after 15 minutes.

Solution

Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Terminal Services -> Terminal Server -> Session Time Limits 'Set time limit for active but idle Terminal Services sessions' to 'Enabled', and the 'Idle session limit' set to 15 minutes or less, excluding 0 which equates to 'Never'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-12, 800-53|SC-10, CAT|II, CCI|CCI-001133, CCI|CCI-002361, Rule-ID|SV-16614r1_rule, STIG-ID|5.047, Vuln-ID|V-3458

Plugin: Windows

Control ID: c5d6257fcc38a883ed3fa0a2405ad8ec79e958ead59267f0cbc31b159c69b1f6