Check: AD.3107_2003
Win2k3 Audit:
AD.3107_2003
(in version v6 r1.29)
Title
The domain controller must be configured to allow reset of machine account passwords. (Cat III impact)
Discussion
Enabling this setting on all domain controllers in a domain prevents domain members from changing their computer account passwords. If these passwords are weak or compromised, the inability to change them may leave these computers vulnerable.
Check Content
Fix Text
Set the value for “Domain Controller: Refuse machine account password changes” to “Disabled”. The policy referenced configures the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \System\CurrentControlSet\Services\Netlogon\Parameters\ Value Name: RefusePasswordChange Value Type: REG_DWORD Value: 0
Additional Identifiers
Rule ID: SV-41842r1_rule
Vulnerability ID: V-4408
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |