Accounts: must disable automatically signing in the last interactive user after a system-initiated restart

30d230a9-ff8e-44a2-ac87-f35b77bff14a

Description
Windows can be configured to automatically sign the user back in after a Windows Update restart. Some protections are in place to help ensure this is done in a secure fashion; however, disabling this will prevent the caching of credentials for this purpose and also ensure the user is aware of the restart

Remediation

To fix this configure the policy value for
Computer Configuration
|_ Administrative Templates
|_ Windows Components
|_ Windows Logon Options
|_ Sign-in last interactive user automatically after a system-initiated restart to "Disabled".

STIG: Server:
2022: https://www.stigviewer.com/stig/microsoft_windows_server_2022/2022-08-25/finding/V-254376
2019: https://www.stigviewer.com/stig/microsoft_windows_server_2019/2022-03-01/finding/V-205925 / https://www.stigviewer.com/stig/windows_server_2019/2020-06-15/finding/V-93269
2016: https://www.stigviewer.com/stig/microsoft_windows_server_2016/2021-09-29/finding/V-224956 / https://www.stigviewer.com/stig/windows_server_2016/2020-06-16/finding/V-73589

Desktop:
W11: https://www.stigviewer.com/stig/microsoft_windows_11/2022-06-24/finding/V-253413
W10: https://www.stigviewer.com/stig/microsoft_windows_10/2022-04-08/finding/V-220859 / https://www.stigviewer.com/stig/windows_10/2021-08-18/finding/V-220859

NIST 800-53: IA-5(13)
NIST 800-171 Rev 3 FPD: 3.5.5.a
NIST 800-171 A rec3 IPD : A.03.01.01.c[02], A.03.01.01.c[03], A.03.01.01.d[01], A.03.01.01.d[02]
CSCv6|16.5
NIST 800-53: AC-11
CIS CSCv7: 16.11