Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-3458 | 5.047 | SV-32495r1_rule | ECSC-1 | Medium |
Description |
---|
This setting controls how long a session may be idle before it is automatically disconnected from the server. Users should disconnect if they plan on being away from their terminals for extended periods of time. Idle sessions should be disconnected after 15 minutes. |
STIG | Date |
---|---|
Windows Server 2008 R2 Domain Controller Security Technical Implementation Guide | 2012-09-05 |
Check Text ( C-39128r1_chk ) |
---|
If the following registry value does not exist or its value is set to 0 or greater than 15 minutes, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows NT\Terminal Services\ Value Name: MaxIdleTime Type: REG_DWORD Value: 0x000dbba0 (900000) or less but not 0 |
Fix Text (F-34278r1_fix) |
---|
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Session Time Limits “Set time limit for active but idle Remote Desktop Services sessions” to “Enabled”, and the “Idle session limit” to 15 minutes or less, excluding 0 which equates to “Never”. |