Windows Server 2022 passwords for the built-in Administrator account must be changed at least every 60 days.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-254239 | WN22-00-000020 | SV-254239r1153440_rule | CCI-004066 | medium |
| Description | ||||
| The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the password. The built-in Administrator account is not generally used and its password may not be changed as frequently as necessary. Changing the password for the built-in Administrator account on a regular basis will limit its exposure. For domain-joined systems, Windows LAPS must be used to change the built-in Administrator account password. | ||||
| STIG | Date | |||
| Microsoft Windows Server 2022 Security Technical Implementation Guide | 2026-02-13 | |||
Details
Check Text (C-254239r1153440_chk)
If there are no enabled local Administrator accounts, this is Not Applicable.
Review the password last set date for the enabled local Administrator account.
On the stand alone or domain-joined server:
Open "PowerShell".
Enter "Get-LocalUser | Where-Object {$_.SID -like "*500"} | ForEach-Object ($_.PasswordLastSet){"$($_.Name) password is: $([int]((Get-Date) - $_.PasswordLastSet).TotalDays) days old"}".
If the "PasswordLastSet" date is greater than "60" days old for the local Administrator account for administering the computer, this is a finding.
Verify LAPS is configured and operational.
If the system is a stand alone member server, the LAPS portion of this requirement is Not Applicable.
Navigate to Local Computer Policy >> Computer Configuration >> Administrative Templates >> System >> LAPS >> Password Settings >> Set to enabled. Password Complexity, large letters + small letters + numbers + special, Password Length 14, Password Age 60. If not configured as shown, this is a finding.
Verify LAPS Operational logs >> Event Viewer >> Applications and Services Logs >> Microsoft >> Windows >> LAPS >> Operational. Verify LAPS policy process is completing. If it is not, this is a finding.
Fix Text (F-57675r1153439_fix)
Change the enabled local Administrator account password at least every 60 days. For domain-joined systems, Windows LAPS must be used to change the built-in Administrator account password.
More information is available at:
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/by-popular-demand-windows-laps-available-now/ba-p/3788747
https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview#windows-laps-supported-platforms-and-azure-ad-laps-preview-status