SV-224994r569186_rule
V-224994
SRG-OS-000105-GPOS-00052
WN16-DC-000310
CAT II
10
Configure all user accounts, including administrator accounts, in Active Directory to enable the option "Smart card is required for interactive logon".
Run "Active Directory Users and Computers" (available from various menus or run "dsa.msc"):
Select the OU where the user accounts are located. (By default this is the Users node; however, accounts may be under other organization-defined OUs.)
Right-click the user account and select "Properties".
Select the "Account" tab.
Check "Smart card is required for interactive logon" in the "Account Options" area.
This applies to domain controllers. It is NA for other systems.
Open "PowerShell".
Enter the following:
"Get-ADUser -Filter {(Enabled -eq $True) -and (SmartcardLogonRequired -eq $False)} | FT Name"
("DistinguishedName" may be substituted for "Name" for more detailed output.)
If any user accounts, including administrators, are listed, this is a finding.
Alternately:
To view sample accounts in "Active Directory Users and Computers" (available from various menus or run "dsa.msc"):
Select the Organizational Unit (OU) where the user accounts are located. (By default, this is the Users node; however, accounts may be under other organization-defined OUs.)
Right-click the sample user account and select "Properties".
Select the "Account" tab.
If any user accounts, including administrators, do not have "Smart card is required for interactive logon" checked in the "Account Options" area, this is a finding.
V-224994
False
WN16-DC-000310
This applies to domain controllers. It is NA for other systems.
Open "PowerShell".
Enter the following:
"Get-ADUser -Filter {(Enabled -eq $True) -and (SmartcardLogonRequired -eq $False)} | FT Name"
("DistinguishedName" may be substituted for "Name" for more detailed output.)
If any user accounts, including administrators, are listed, this is a finding.
Alternately:
To view sample accounts in "Active Directory Users and Computers" (available from various menus or run "dsa.msc"):
Select the Organizational Unit (OU) where the user accounts are located. (By default, this is the Users node; however, accounts may be under other organization-defined OUs.)
Right-click the sample user account and select "Properties".
Select the "Account" tab.
If any user accounts, including administrators, do not have "Smart card is required for interactive logon" checked in the "Account Options" area, this is a finding.
M
4205