UCF STIG Viewer Logo

The password history must be configured to 24 passwords.


Overview

Finding ID Version Rule ID IA Controls Severity
V-1107 4.014 SV-32290r2_rule IAIA-1 IAIA-2 Medium
Description
A system is more vulnerable to unauthorized access when users can recycle the same password several times without being required to change it to a unique password on a regularly scheduled basis. This enables users to effectively negate the purpose of mandating periodic password changes.
STIG Date
Windows Server 2008 R2 Domain Controller Security Technical Implementation Guide 2015-06-16

Details

Check Text ( C-60981r2_chk )
Analyze the system using the Security Configuration and Analysis snap-in.
Expand the Security Configuration and Analysis tree view.
Navigate to Account Policies >> Password Policy.

If the value for "Enforce password history" is less than "24" passwords, this is a finding.
Fix Text (F-65711r2_fix)
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Enforce password history" to "24" passwords remembered.