Check: AD.3107_2008_R2
Win2k8 R2 Audit:
AD.3107_2008_R2
(in version v1 r8)
Title
The domain controller must be configured to allow reset of machine account passwords. (Cat III impact)
Discussion
Enabling this setting on all domain controllers in a domain prevents domain members from changing their computer account passwords. If these passwords are weak or compromised, the inability to change them may leave these computers vulnerable.
Check Content
Fix Text
Set the value for “Domain Controller: Refuse machine account password changes” to “Disabled”. The policy referenced configures the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \System\CurrentControlSet\Services\Netlogon\Parameters\ Value Name: RefusePasswordChange Value Type: REG_DWORD Value: 0
Additional Identifiers
Rule ID: SV-36192r1_rule
Vulnerability ID: V-4408
Group Title: AD.3107 Computer Account Password Change
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |