3.070 - The system is configured to permit storage of credentials or .NET Passports.

Information

This setting controls the storage of authentication credentials or .NET passports on the local system. Such credentials should never be stored on the local machine as that may lead to account compromise.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Network access- Do not allow storage of credentials or .NET passports for network authentication' to 'Enabled'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-11, CAT|II, CCI|CCI-002038, Rule-ID|SV-29258r1_rule, STIG-ID|3.070, Vuln-ID|V-3376

Plugin: Windows

Control ID: 2be36f1f88ea81b44ec0004419799e79e1667b367b9ca952759f45e30c9e6197