Accounts must be configured to require password expiration.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-220716 | WN10-00-000090 | SV-220716r1051019_rule | CCI-004066 | medium |
| Description | ||||
| Passwords that do not expire increase exposure with a greater probability of being discovered or cracked. | ||||
| STIG | Date | |||
| Microsoft Windows 10 Security Technical Implementation Guide | 2025-02-25 | |||
Details
Check Text (C-220716r1051019_chk)
Run "Computer Management".
Navigate to System Tools >> Local Users and Groups >> Users.
Double-click each active account.
If "Password never expires" is selected for any account, this is a finding.
Fix Text (F-22420r997900_fix)
Configure all passwords to expire.
Run "Computer Management".
Navigate to System Tools >> Local Users and Groups >> Users.
Double-click each active account.
Ensure "Password never expires" is not checked on all active accounts.