Check: 3.131
Windows Vista STIG:
3.131
(in versions v6 r42 through v6 r41)
Title
User Account Control - Behavior of elevation prompt for standard users. (Cat II impact)
Discussion
This check verifies whether the logged on user is prompted for credentials when attempting to complete a task that requires raised privileges.
Check Content
Analyze the system using the Security Configuration and Analysis snap-in. Expand the Security Configuration and Analysis tree view. Navigate to Local Policies -> Security Options. If the value for “User Account Control: Behavior of the elevation prompt for standard users” is not set to “Prompt for credentials”, then this is a finding. The policy referenced configures the following registry value: Registry Path: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ Value Name: ConsentPromptBehaviorUser Value Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “User Account Control: Behavior of the elevation prompt for standard users” to “Prompt for credentials”.
Additional Identifiers
Rule ID: SV-14847r1_rule
Vulnerability ID: V-14236
Group Title: UAC - User Elevation Prompt
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002038 |
The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication. |
Controls
Number | Title |
---|---|
IA-11 |
Re-Authentication |