Windows 10 nonpersistent VM sessions must not exceed 24 hours.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-220738
WN10-00-000250
SV-220738r958552_rule
Medium
Description
For virtual desktop implementations (VDIs) where the virtual desktop instance is deleted or refreshed upon logoff, the organization should enforce that sessions be terminated within 24 hours. This would ensure any data stored on the VM that is not encrypted or covered by Credential Guard is deleted.
Ensure there is a documented policy or procedure in place that nonpersistent VM sessions do not exceed 24 hours. If the system is NOT a nonpersistent VM, this is Not Applicable.
If no such documented policy or procedure is in place, this is a finding.
Fix Text (F-22442r890425_fix)
Set nonpersistent VM sessions to not exceed 24 hours.