Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-3453 | 5.042 | SV-3453r1_rule | IAIA-1 IAIA-2 | Medium |
Description |
---|
This setting, which is located under the Encryption and Security section of the Terminal Services configuration option, controls the ability of users to supply passwords automatically as part of their Remote Desktop Connection. Disabling this setting would allow anyone to use the stored credentials in a connection item to connect to the terminal server. |
STIG | Date |
---|---|
Windows XP Security Technical Implementation Guide | 2014-04-07 |
Check Text ( None ) |
---|
None |
Fix Text (F-5922r1_fix) |
---|
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Terminal Services -> Encryption and Security “Always Prompt Client for Password upon Connection” to “Enabled”. |