WN12-CC-000145 - Automatically signing in the last interactive user after a system-initiated restart must be disabled (Windows 2012 R2).

Information

Windows 2012 R2 can be configured to automatically sign the user back in after a Windows Update restart. Some protections are in place to help ensure this is done in a secure fashion; however, disabling this will prevent the caching of credentials for this purpose and also ensure the user is aware of the restart.

Solution

This requirement is NA for the initial release of Windows 2012. It is applicable to Windows 2012 R2.

Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Logon Options -> 'Sign-in last interactive user automatically after a system-initiated restart' to 'Disabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-225414r569185_rule, STIG-ID|WN12-CC-000145, STIG-Legacy|SV-56355, STIG-Legacy|V-43245, Vuln-ID|V-225414

Plugin: Windows

Control ID: 728935912f810d950b3c6ab364b4f8584dcf5c343f519a37177e88151a239ab7