SV-205629r569188_rule
V-205629
SRG-OS-000021-GPOS-00005
WN19-AC-000020
CAT II
10
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy >> "Account lockout threshold" to "3" or fewer invalid logon attempts (excluding "0", which is unacceptable).
Verify the effective setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy.
If the "Account lockout threshold" is "0" or more than "3" attempts, this is a finding.
For server core installations, run the following command:
Secedit /Export /Areas SecurityPolicy /CFG C:\Path\FileName.Txt
If "LockoutBadCount" equals "0" or is greater than "3" in the file, this is a finding.
V-205629
False
WN19-AC-000020
Verify the effective setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy.
If the "Account lockout threshold" is "0" or more than "3" attempts, this is a finding.
For server core installations, run the following command:
Secedit /Export /Areas SecurityPolicy /CFG C:\Path\FileName.Txt
If "LockoutBadCount" equals "0" or is greater than "3" in the file, this is a finding.
M
2907