UCF STIG Viewer Logo

Local users exist on a workstation in a domain.


Overview

Finding ID Version Rule ID IA Controls Severity
V-1148 4.024 SV-25214r1_rule IAAC-1 Low
Description
To minimize potential points of attack, local users, other than built-in accounts such as Administrator and Guest accounts, should not exist on a workstation in a domain. Users should always log onto workstations in a domain with their domain accounts.
STIG Date
Windows 7 Security Technical Implementation Guide 2014-04-02

Details

Check Text ( C-26817r1_chk )
Windows 7 - Use the DUMPSEC utility.
Select “Dump Users as Table” from the “Report” menu.
Select the available fields in the following sequence, and click on the “Add” button for each entry:

UserName
SID
PswdRequired
PswdExpires
LastLogonTime
AcctDisabled
Groups

If local users other than the built-in accounts listed below exist on a workstation in a domain, this is a finding:

Built-in Administrator (renamed)
Built-in Guest (renamed)

Documentable Explanation: If a site has need of special purpose local user accounts, then this should be documented with the IAO.

Fix Text (F-5764r1_fix)
Configure the system to restrict the existence of local user accounts.