UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Remote Desktop Services must be configured to disconnect an idle session after the specified time period.


Overview

Finding ID Version Rule ID IA Controls Severity
V-3458 WN12-CC-000101 SV-52903r2_rule ECSC-1 Medium
Description
This setting controls how long a session may be idle before it is automatically disconnected from the server. Users must disconnect if they plan on being away from their terminals for extended periods of time. Idle sessions must be disconnected after 15 minutes.
STIG Date
Windows Server 2012 / 2012 R2 Member Server Security Technical Implementation Guide 2015-06-16

Details

Check Text ( C-47220r2_chk )
If the following registry value does not exist or its value is set to "0" or greater than "15" minutes, this is a finding:

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \Software\Policies\Microsoft\Windows NT\Terminal Services\

Value Name: MaxIdleTime

Type: REG_DWORD
Value: 0x000dbba0 (900000) or less but not 0
Fix Text (F-45829r1_fix)
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Session Time Limits -> "Set time limit for active but idle Remote Desktop Services sessions" to "Enabled", and the "Idle session limit" to 15 minutes or less, excluding "0", which equates to "Never".