Accounts must be configured to require password expiration.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-253273 | SRG-OS-000076-GPOS-00044 | WN11-00-000090 | SV-253273r1051040_rule | 2026-02-12 | 2 |
Description
Passwords that do not expire increase exposure with a greater probability of being discovered or cracked.
ℹ️ Check
Run "Computer Management".
Navigate to System Tools >> Local Users and Groups >> Users.
Double-click each active account.
If "Password never expires" is selected for any account, this is a finding.
✔️ Fix
Configure all passwords to expire.
Run "Computer Management".
Navigate to System Tools >> Local Users and Groups >> Users.
Double-click each active account.
Ensure "Password never expires" is not checked on all active accounts.