Check: WN08-SO-000001
Windows 8/8.1 STIG:
WN08-SO-000001
(in versions v1 r23 through v1 r16)
Title
The built-in administrator account must be disabled. (Cat II impact)
Discussion
The built-in administrator account is a well-known account subject to attack. It also provides no accountability to individual administrators on a system. It must be disabled to prevent its use.
Check Content
Analyze the system using the Security Configuration and Analysis snap-in. (See "Performing Analysis with the Security Configuration and Analysis Snap-in" in the STIG Overview document.) Expand the Security Configuration and Analysis tree view. Navigate to Local Policies -> Security Options. If the value for "Accounts: Administrator account status" is not set to "Disabled", this is a finding.
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Accounts: Administrator account status" to "Disabled".
Additional Identifiers
Rule ID: SV-48262r1_rule
Vulnerability ID: V-16047
Group Title: Built-in Admin Account Status
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000764 |
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. |
Controls
Number | Title |
---|---|
IA-2 |
Identification and Authentication (organizational Users) |