Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 11 checks on this page
- 1.1 Password Policy
- Ensure Enforce Password History Is 24 Or More Passwords
- Ensure Maximum Password Age Is 365 Or Fewer Days And Not Zero
- Ensure Minimum Password Age Is One Or More Days
- Ensure Minimum Password Length Is 14 Or More Characters
- Ensure Password Complexity Requirements Are Enabled
- Ensure Relax Minimum Password Length Limits Is Enabled
- Ensure Store Passwords Using Reversible Encryption Is Disabled
- 1.2 Account Lockout Policy
- Ensure Account Lockout Duration Is 15 Or More Minutes
- Ensure Account Lockout Threshold Is Five Or Fewer Attempts And Not Zero
- Ensure Allow Administrator Account Lockout Is Enabled
- Ensure Reset Account Lockout Counter Is 15 Or More Minutes
1.1 Password Policy
Ensure Enforce Password History Is 24 Or More Passwords
Finding: Enforce password history is fewer than 24 passwords.
Checks the number of previous passwords remembered before an old password can be reused.
This rule fails when passwordHistLength is less than 24.
Rationale: Reusing old passwords lets a compromised or brute-forced credential remain usable; a long history reduces reuse.
Impact: Users must choose a new password each change and cannot cycle back to a recent one.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy and set Enforce password history to 24 or more password(s).
From the command line:
net accounts /uniquepw:24
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Maximum Password Age Is 365 Or Fewer Days And Not Zero
Finding: Maximum password age is 0 or exceeds 365 days.
Checks how many days a password may be used before it must be changed.
This rule fails when maxPasswdAge is 0 or greater than 365.
Rationale: A value of 0 lets passwords live forever; an excessively long age gives an attacker more time to use a cracked credential.
Impact: Users are required to change their password at least once per year.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy and set Maximum password age to 365 or fewer days, but not 0.
From the command line:
net accounts /maxpwage:365
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Minimum Password Age Is One Or More Days
Finding: Minimum password age is set to 0 days.
Checks the number of days a password must be kept before it can be changed.
This rule fails when minPasswdAge is less than 1.
Rationale: Without a minimum age, a user can cycle through the password history in minutes to return to a favourite password, defeating history enforcement.
Impact: Users cannot change a password more than once within the configured minimum period.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy and set Minimum password age to 1 or more day(s).
From the command line:
net accounts /minpwage:1
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Minimum Password Length Is 14 Or More Characters
Finding: Minimum password length is below 14 characters.
Checks the least number of characters a password must contain.
This rule fails when minPasswdLen is less than 14.
Rationale: Short passwords fall quickly to dictionary and brute-force attacks; longer minimums greatly increase the work required to crack them.
Impact: Users must choose passwords of at least 14 characters.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy and set Minimum password length to 14 or more character(s).
From the command line:
net accounts /minpwlen:14
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Password Complexity Requirements Are Enabled
Finding: Password complexity requirements are disabled.
Checks whether new passwords must include a mix of character categories and exclude the account name.
This rule fails when passwordMeetsComplexityRequirements is false.
Rationale: Complexity requirements block trivially guessable passwords and raise the cost of brute-force and dictionary attacks.
Impact: Users must choose passwords that satisfy the complexity categories.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy and set Password must meet complexity requirements to Enabled.
From the command line:
secedit /export /cfg C:\Windows\Temp\secpol.cfg /quiet
powershell -Command "(Get-Content C:\Windows\Temp\secpol.cfg) -replace 'PasswordComplexity = 0','PasswordComplexity = 1' | Set-Content C:\Windows\Temp\secpol.cfg"
secedit /configure /db C:\Windows\security\local.sdb /cfg C:\Windows\Temp\secpol.cfg /areas SECURITYPOLICY /quiet
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Relax Minimum Password Length Limits Is Enabled
Finding: Relax minimum password length limits is disabled.
Checks whether the minimum password length can be raised beyond the legacy 14-character cap.
This rule fails when relaxMinPasswordLengthLimit is false.
Rationale: Enabling this lifts the 14-character ceiling so longer minimum lengths can be enforced.
Impact: Administrators may configure minimum password lengths greater than 14 characters.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy and set Relax minimum password length limits to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\SAM" /v RelaxMinimumPasswordLengthLimits /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Store Passwords Using Reversible Encryption Is Disabled
Finding: Passwords are stored using reversible encryption.
Checks whether the OS stores account passwords in a recoverable (reversible) form.
This rule fails when storesPasswordsUsingReversibleEncryption is true.
Rationale: Reversible storage is effectively plaintext to anyone who obtains the database, exposing every credential.
Impact: Applications that require reversible password retrieval will no longer function.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy and set Store passwords using reversible encryption to Disabled.
From the command line:
secedit /export /cfg C:\Windows\Temp\secpol.cfg /quiet
powershell -Command "(Get-Content C:\Windows\Temp\secpol.cfg) -replace 'ClearTextPassword = 1','ClearTextPassword = 0' | Set-Content C:\Windows\Temp\secpol.cfg"
secedit /configure /db C:\Windows\security\local.sdb /cfg C:\Windows\Temp\secpol.cfg /areas SECURITYPOLICY /quiet
- Framework mappings
- CIS Controls v8: 3.11 Encrypt Sensitive Data at Rest
- NIST SP 800-53 Rev. 5: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
- CMMC 2.0 Level 2: MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
1.2 Account Lockout Policy
Ensure Account Lockout Duration Is 15 Or More Minutes
Finding: Account lockout duration is less than 15 minutes.
Checks how long (in minutes) a locked-out account stays locked before it can be used again.
This rule fails when accountLockoutDuration is less than 15 minutes.
Rationale: A longer lockout duration slows password-guessing attacks by forcing the attacker to wait after hitting the threshold.
Impact: Users locked out by failed logons must wait the configured duration or contact an administrator.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy and set Account lockout duration to 15 or more minute(s).
From the command line:
net accounts /lockoutduration:15
- Framework mappings
- CIS Controls v8: 4.10 Enforce Automatic Device Lockout on Portable End-User Devices
- NIST SP 800-53 Rev. 5: AC-7 Unsuccessful Logon Attempts; AC-19 Access Control for Mobile Devices
- NIST SP 800-171 Rev. 2: 3.1.8 Limit unsuccessful logon attempts
- CMMC 2.0 Level 2: AC.L2-3.1.8 Limit unsuccessful logon attempts
- PCI DSS v4.0.1: 8.3.4 Lock accounts after 10 failed logins for at least 30 minutes
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Account Lockout Threshold Is Five Or Fewer Attempts And Not Zero
Finding: Account lockout threshold is 0 or exceeds 5 attempts.
Checks the number of failed logon attempts allowed before the account is locked.
This rule fails when accountLockoutThreshold is 0 or greater than 5.
Rationale: A threshold of 0 never locks an account, allowing unlimited password guessing; a low non-zero value throttles brute-force attempts.
Impact: Accounts lock after the configured number of failed attempts, which may generate help-desk calls.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy and set Account lockout threshold to 5 or fewer invalid logon attempt(s), but not 0.
From the command line:
net accounts /lockoutthreshold:5
- Framework mappings
- CIS Controls v8: 4.10 Enforce Automatic Device Lockout on Portable End-User Devices
- NIST SP 800-53 Rev. 5: AC-7 Unsuccessful Logon Attempts; AC-19 Access Control for Mobile Devices
- NIST SP 800-171 Rev. 2: 3.1.8 Limit unsuccessful logon attempts
- CMMC 2.0 Level 2: AC.L2-3.1.8 Limit unsuccessful logon attempts
- PCI DSS v4.0.1: 8.3.4 Lock accounts after 10 failed logins for at least 30 minutes
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Allow Administrator Account Lockout Is Enabled
Finding: Allow Administrator account lockout is disabled.
Checks whether the built-in Administrator account is subject to the account lockout policy.
This rule fails when allowAdministratorAccountLockout is false.
Rationale: Without this, the built-in Administrator is exempt from lockout and can be brute-forced without limit.
Impact: The built-in Administrator account can be locked out by repeated failed logons.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy and set Allow Administrator account lockout to Enabled.
From the command line:
secedit /export /cfg C:\Windows\Temp\secpol.cfg /quiet
powershell -Command "(Get-Content C:\Windows\Temp\secpol.cfg) -replace 'AllowAdministratorLockout = 0','AllowAdministratorLockout = 1' | Set-Content C:\Windows\Temp\secpol.cfg"
secedit /configure /db C:\Windows\security\local.sdb /cfg C:\Windows\Temp\secpol.cfg /areas SECURITYPOLICY /quiet
- Framework mappings
- CIS Controls v8: 4.10 Enforce Automatic Device Lockout on Portable End-User Devices
- NIST SP 800-53 Rev. 5: AC-7 Unsuccessful Logon Attempts; AC-19 Access Control for Mobile Devices
- NIST SP 800-171 Rev. 2: 3.1.8 Limit unsuccessful logon attempts
- CMMC 2.0 Level 2: AC.L2-3.1.8 Limit unsuccessful logon attempts
- PCI DSS v4.0.1: 8.3.4 Lock accounts after 10 failed logins for at least 30 minutes
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Reset Account Lockout Counter Is 15 Or More Minutes
Finding: Reset account lockout counter is less than 15 minutes.
Checks the time that must pass after a failed logon before the bad-logon counter resets to 0.
This rule fails when resetAccountLockoutCounterAfter is less than 900000000000 ns (15 minutes).
Rationale: A short reset window lets an attacker spread guesses over time without ever tripping the lockout threshold.
Impact: The failed-logon counter persists for at least 15 minutes between attempts.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy and set Reset account lockout counter after to 15 or more minute(s).
From the command line:
net accounts /lockoutwindow:15
- Framework mappings
- CIS Controls v8: 4.10 Enforce Automatic Device Lockout on Portable End-User Devices
- NIST SP 800-53 Rev. 5: AC-7 Unsuccessful Logon Attempts; AC-19 Access Control for Mobile Devices
- NIST SP 800-171 Rev. 2: 3.1.8 Limit unsuccessful logon attempts
- CMMC 2.0 Level 2: AC.L2-3.1.8 Limit unsuccessful logon attempts
- PCI DSS v4.0.1: 8.3.4 Lock accounts after 10 failed logins for at least 30 minutes
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)