SV-226069r569184_rule
V-226069
SRG-OS-000112-GPOS-00057
WN12-AC-000014-DC
CAT II
10
Configure the policy value in the Default Domain Policy for Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Kerberos Policy -> "Maximum tolerance for computer clock synchronization" to a maximum of 5 minutes or less.
Verify the following is configured in the Default Domain Policy.
Open "Group Policy Management".
Navigate to "Group Policy Objects" in the Domain being reviewed (Forest > Domains > Domain).
Right click on the "Default Domain Policy".
Select Edit.
Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Kerberos Policy.
If the "Maximum tolerance for computer clock synchronization" is greater than 5 minutes, this is a finding.
V-226069
False
WN12-AC-000014-DC
Verify the following is configured in the Default Domain Policy.
Open "Group Policy Management".
Navigate to "Group Policy Objects" in the Domain being reviewed (Forest > Domains > Domain).
Right click on the "Default Domain Policy".
Select Edit.
Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Kerberos Policy.
If the "Maximum tolerance for computer clock synchronization" is greater than 5 minutes, this is a finding.
M
4217