---
title: CIS Windows 11 Account Policies: 11 Checks | Wartiva
description: Wartiva's 11 checks for section 1, Account Policies, of the CIS Microsoft Windows 11 Stand-alone Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 1

# Windows 11 Account Policies: 11 Checks

Wartiva runs 11 checks for section 1, Account Policies, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## 1.1 Password Policy

### [Ensure Enforce Password History Is 24 Or More Passwords](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#enforce-password-history-is-24-or-more-passwords)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.1

**Finding:** Enforce password history is fewer than 24 passwords.

Checks the number of previous passwords remembered before an old password can be reused.

This rule fails when `passwordHistLength` is less than `24`.

**Rationale:** Reusing old passwords lets a compromised or brute-forced credential remain usable; a long history reduces reuse.

**Impact:** Users must choose a new password each change and cannot cycle back to a recent one.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy** and set **Enforce password history** to **24 or more password(s)**.

From the command line:

```powershell
net accounts /uniquepw:24
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Maximum Password Age Is 365 Or Fewer Days And Not Zero](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#maximum-password-age-is-365-or-fewer-days-and-not-zero)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.1

**Finding:** Maximum password age is 0 or exceeds 365 days.

Checks how many days a password may be used before it must be changed.

This rule fails when `maxPasswdAge` is `0` or greater than `365`.

**Rationale:** A value of 0 lets passwords live forever; an excessively long age gives an attacker more time to use a cracked credential.

**Impact:** Users are required to change their password at least once per year.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy** and set **Maximum password age** to **365 or fewer days, but not 0**.

From the command line:

```powershell
net accounts /maxpwage:365
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Minimum Password Age Is One Or More Days](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#minimum-password-age-is-one-or-more-days)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.1

**Finding:** Minimum password age is set to 0 days.

Checks the number of days a password must be kept before it can be changed.

This rule fails when `minPasswdAge` is less than `1`.

**Rationale:** Without a minimum age, a user can cycle through the password history in minutes to return to a favourite password, defeating history enforcement.

**Impact:** Users cannot change a password more than once within the configured minimum period.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy** and set **Minimum password age** to **1 or more day(s)**.

From the command line:

```powershell
net accounts /minpwage:1
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Minimum Password Length Is 14 Or More Characters](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#minimum-password-length-is-14-or-more-characters)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.1

**Finding:** Minimum password length is below 14 characters.

Checks the least number of characters a password must contain.

This rule fails when `minPasswdLen` is less than `14`.

**Rationale:** Short passwords fall quickly to dictionary and brute-force attacks; longer minimums greatly increase the work required to crack them.

**Impact:** Users must choose passwords of at least 14 characters.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy** and set **Minimum password length** to **14 or more character(s)**.

From the command line:

```powershell
net accounts /minpwlen:14
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Password Complexity Requirements Are Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#password-complexity-requirements-are-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.1

**Finding:** Password complexity requirements are disabled.

Checks whether new passwords must include a mix of character categories and exclude the account name.

This rule fails when `passwordMeetsComplexityRequirements` is `false`.

**Rationale:** Complexity requirements block trivially guessable passwords and raise the cost of brute-force and dictionary attacks.

**Impact:** Users must choose passwords that satisfy the complexity categories.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy** and set **Password must meet complexity requirements** to **Enabled**.

From the command line:

```powershell
secedit /export /cfg C:\Windows\Temp\secpol.cfg /quiet
powershell -Command "(Get-Content C:\Windows\Temp\secpol.cfg) -replace 'PasswordComplexity = 0','PasswordComplexity = 1' | Set-Content C:\Windows\Temp\secpol.cfg"
secedit /configure /db C:\Windows\security\local.sdb /cfg C:\Windows\Temp\secpol.cfg /areas SECURITYPOLICY /quiet
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Relax Minimum Password Length Limits Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#relax-minimum-password-length-limits-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.1

**Finding:** Relax minimum password length limits is disabled.

Checks whether the minimum password length can be raised beyond the legacy 14-character cap.

This rule fails when `relaxMinPasswordLengthLimit` is `false`.

**Rationale:** Enabling this lifts the 14-character ceiling so longer minimum lengths can be enforced.

**Impact:** Administrators may configure minimum password lengths greater than 14 characters.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy** and set **Relax minimum password length limits** to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Control\SAM" /v RelaxMinimumPasswordLengthLimits /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Store Passwords Using Reversible Encryption Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#store-passwords-using-reversible-encryption-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.1

**Finding:** Passwords are stored using reversible encryption.

Checks whether the OS stores account passwords in a recoverable (reversible) form.

This rule fails when `storesPasswordsUsingReversibleEncryption` is `true`.

**Rationale:** Reversible storage is effectively plaintext to anyone who obtains the database, exposing every credential.

**Impact:** Applications that require reversible password retrieval will no longer function.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy** and set **Store passwords using reversible encryption** to **Disabled**.

From the command line:

```powershell
secedit /export /cfg C:\Windows\Temp\secpol.cfg /quiet
powershell -Command "(Get-Content C:\Windows\Temp\secpol.cfg) -replace 'ClearTextPassword = 1','ClearTextPassword = 0' | Set-Content C:\Windows\Temp\secpol.cfg"
secedit /configure /db C:\Windows\security\local.sdb /cfg C:\Windows\Temp\secpol.cfg /areas SECURITYPOLICY /quiet
```

Framework mappings

- **CIS Controls v8**: 3.11 Encrypt Sensitive Data at Rest
- **NIST SP 800-53 Rev. 5**: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
- **CMMC 2.0 Level 2**: MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- **PCI DSS v4.0.1**: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 1.2 Account Lockout Policy

### [Ensure Account Lockout Duration Is 15 Or More Minutes](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#account-lockout-duration-is-15-or-more-minutes)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.2

**Finding:** Account lockout duration is less than 15 minutes.

Checks how long (in minutes) a locked-out account stays locked before it can be used again.

This rule fails when `accountLockoutDuration` is less than `15` minutes.

**Rationale:** A longer lockout duration slows password-guessing attacks by forcing the attacker to wait after hitting the threshold.

**Impact:** Users locked out by failed logons must wait the configured duration or contact an administrator.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy** and set **Account lockout duration** to **15 or more minute(s)**.

From the command line:

```powershell
net accounts /lockoutduration:15
```

Framework mappings

- **CIS Controls v8**: 4.10 Enforce Automatic Device Lockout on Portable End-User Devices
- **NIST SP 800-53 Rev. 5**: AC-7 Unsuccessful Logon Attempts; AC-19 Access Control for Mobile Devices
- **NIST SP 800-171 Rev. 2**: 3.1.8 Limit unsuccessful logon attempts
- **CMMC 2.0 Level 2**: AC.L2-3.1.8 Limit unsuccessful logon attempts
- **PCI DSS v4.0.1**: 8.3.4 Lock accounts after 10 failed logins for at least 30 minutes

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Account Lockout Threshold Is Five Or Fewer Attempts And Not Zero](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#account-lockout-threshold-is-five-or-fewer-attempts-and-not-zero)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.2

**Finding:** Account lockout threshold is 0 or exceeds 5 attempts.

Checks the number of failed logon attempts allowed before the account is locked.

This rule fails when `accountLockoutThreshold` is `0` or greater than `5`.

**Rationale:** A threshold of 0 never locks an account, allowing unlimited password guessing; a low non-zero value throttles brute-force attempts.

**Impact:** Accounts lock after the configured number of failed attempts, which may generate help-desk calls.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy** and set **Account lockout threshold** to **5 or fewer invalid logon attempt(s), but not 0**.

From the command line:

```powershell
net accounts /lockoutthreshold:5
```

Framework mappings

- **CIS Controls v8**: 4.10 Enforce Automatic Device Lockout on Portable End-User Devices
- **NIST SP 800-53 Rev. 5**: AC-7 Unsuccessful Logon Attempts; AC-19 Access Control for Mobile Devices
- **NIST SP 800-171 Rev. 2**: 3.1.8 Limit unsuccessful logon attempts
- **CMMC 2.0 Level 2**: AC.L2-3.1.8 Limit unsuccessful logon attempts
- **PCI DSS v4.0.1**: 8.3.4 Lock accounts after 10 failed logins for at least 30 minutes

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Allow Administrator Account Lockout Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#allow-administrator-account-lockout-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.2

**Finding:** Allow Administrator account lockout is disabled.

Checks whether the built-in Administrator account is subject to the account lockout policy.

This rule fails when `allowAdministratorAccountLockout` is `false`.

**Rationale:** Without this, the built-in Administrator is exempt from lockout and can be brute-forced without limit.

**Impact:** The built-in Administrator account can be locked out by repeated failed logons.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy** and set **Allow Administrator account lockout** to **Enabled**.

From the command line:

```powershell
secedit /export /cfg C:\Windows\Temp\secpol.cfg /quiet
powershell -Command "(Get-Content C:\Windows\Temp\secpol.cfg) -replace 'AllowAdministratorLockout = 0','AllowAdministratorLockout = 1' | Set-Content C:\Windows\Temp\secpol.cfg"
secedit /configure /db C:\Windows\security\local.sdb /cfg C:\Windows\Temp\secpol.cfg /areas SECURITYPOLICY /quiet
```

Framework mappings

- **CIS Controls v8**: 4.10 Enforce Automatic Device Lockout on Portable End-User Devices
- **NIST SP 800-53 Rev. 5**: AC-7 Unsuccessful Logon Attempts; AC-19 Access Control for Mobile Devices
- **NIST SP 800-171 Rev. 2**: 3.1.8 Limit unsuccessful logon attempts
- **CMMC 2.0 Level 2**: AC.L2-3.1.8 Limit unsuccessful logon attempts
- **PCI DSS v4.0.1**: 8.3.4 Lock accounts after 10 failed logins for at least 30 minutes

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Reset Account Lockout Counter Is 15 Or More Minutes](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/account-policies.html#reset-account-lockout-counter-is-15-or-more-minutes)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 1.2

**Finding:** Reset account lockout counter is less than 15 minutes.

Checks the time that must pass after a failed logon before the bad-logon counter resets to 0.

This rule fails when `resetAccountLockoutCounterAfter` is less than `900000000000` ns (15 minutes).

**Rationale:** A short reset window lets an attacker spread guesses over time without ever tripping the lockout threshold.

**Impact:** The failed-logon counter persists for at least 15 minutes between attempts.

#### Remediation

Open **Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy** and set **Reset account lockout counter after** to **15 or more minute(s)**.

From the command line:

```powershell
net accounts /lockoutwindow:15
```

Framework mappings

- **CIS Controls v8**: 4.10 Enforce Automatic Device Lockout on Portable End-User Devices
- **NIST SP 800-53 Rev. 5**: AC-7 Unsuccessful Logon Attempts; AC-19 Access Control for Mobile Devices
- **NIST SP 800-171 Rev. 2**: 3.1.8 Limit unsuccessful logon attempts
- **CMMC 2.0 Level 2**: AC.L2-3.1.8 Limit unsuccessful logon attempts
- **PCI DSS v4.0.1**: 8.3.4 Lock accounts after 10 failed logins for at least 30 minutes

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
