UCF STIG Viewer Logo

The password history must be configured to 24 passwords remembered.


Overview

Finding ID Version Rule ID IA Controls Severity
V-63415 WN10-AC-000020 SV-77905r1_rule Medium
Description
A system is more vulnerable to unauthorized access when system users recycle the same password several times without being required to change a password to a unique password on a regularly scheduled basis. This enables users to effectively negate the purpose of mandating periodic password changes.
STIG Date
Windows 10 Security Technical Implementation Guide 2016-01-07

Details

Check Text ( None )
None
Fix Text (F-69343r1_fix)
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Enforce password history" to "24" passwords remembered.