5.132 - Require username and password to elevate a running application.

Information

This check verifies that the system is configured to always require users to type in a user name and password to elevate a running application.

Solution

Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Credential User Interface 'Enumerate administrator accounts on elevation' to 'Disabled'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-3, CAT|II, CCI|CCI-001084, Rule-ID|SV-14854r1_rule, STIG-ID|5.132, Vuln-ID|V-14243

Plugin: Windows

Control ID: cadf20ca29f911fdc45fb90bfc198927fe1d8efb4517a62c2461de204422b12d