UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Accounts must be configured to require password expiration.


Overview

Finding ID Version Rule ID IA Controls Severity
V-63371 WN10-00-000090 SV-77861r1_rule Medium
Description
Passwords that do not expire increase exposure with a greater probability of being discovered or cracked.
STIG Date
Windows 10 Security Technical Implementation Guide 2017-02-21

Details

Check Text ( C-64111r1_chk )
Run "Computer Management".
Navigate to System Tools >> Local Users and Groups >> Users.
Double click each active account.

If "Password never expires" is selected for any account, this is a finding.
Fix Text (F-69291r1_fix)
Configure all passwords to expire.
Run "Computer Management".
Navigate to System Tools >> Local Users and Groups >> Users.
Double click each active account.
Ensure "Password never expires" is not checked on all active accounts.