The VMM must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-207342SRG-OS-000021SRG-OS-000021-VMM-000050SV-207342r958388_rule2024-12-062
Description
By limiting the number of failed login attempts, the risk of unauthorized VMM access via user password guessing, otherwise known as brute-forcing, is reduced. Limits are imposed by locking the account. This restriction may be relaxed for administrative accounts to avoid potential Denial of Service.
ℹ️ Check
Verify the VMM enforces the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. If it does not, this is a finding.
✔️ Fix
Configure the VMM to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period, by locking the account.