SV-226068r569184_rule
V-226068
SRG-OS-000480-GPOS-00227
WN12-AC-000013-DC
CAT II
10
Configure the policy value in the Default Domain Policy for Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Account Policies -> Kerberos Policy -> "Maximum lifetime for user ticket renewal" to a maximum of 7 days or less.
Verify the following is configured in the Default Domain Policy.
Open "Group Policy Management".
Navigate to "Group Policy Objects" in the Domain being reviewed (Forest > Domains > Domain).
Right click on the "Default Domain Policy".
Select Edit.
Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Kerberos Policy.
If the "Maximum lifetime for user ticket renewal" is greater than 7 days, this is a finding.
V-226068
False
WN12-AC-000013-DC
Verify the following is configured in the Default Domain Policy.
Open "Group Policy Management".
Navigate to "Group Policy Objects" in the Domain being reviewed (Forest > Domains > Domain).
Right click on the "Default Domain Policy".
Select Edit.
Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Kerberos Policy.
If the "Maximum lifetime for user ticket renewal" is greater than 7 days, this is a finding.
M
4217