WN12-CC-000076 - The password reveal button must not be displayed.

Information

Visible passwords may be seen by nearby persons, compromising them. The password reveal button can be used to display an entered password and must not be allowed.

Solution

Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Credential User Interface -> 'Do not display the password reveal button' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-6, CAT|II, CCI|CCI-000206, Rule-ID|SV-225368r569185_rule, STIG-ID|WN12-CC-000076, STIG-Legacy|SV-51740, STIG-Legacy|V-36700, Vuln-ID|V-225368

Plugin: Windows

Control ID: a57824969affe87c8a98d6126fdf8a65927158a8bdc5296e6bb096f162c05edb