30d230a9-ff8e-44a2-ac87-f35b77bff14a
Description
Windows can be configured to automatically sign the user back in after a Windows Update restart. Some protections are in place to help ensure this is done in a secure fashion; however, disabling this will prevent the caching of credentials for this purpose and also ensure the user is aware of the restart
To fix this configure the policy value for
Computer Configuration
|_ Administrative Templates
|_ Windows Components
|_ Windows Logon Options
|_ Sign-in last interactive user automatically after a system-initiated restart to "Disabled".
STIG: Server:
2022: https://www.stigviewer.com/stig/microsoft_windows_server_2022/2022-08-25/finding/V-254376
2019: https://www.stigviewer.com/stig/microsoft_windows_server_2019/2022-03-01/finding/V-205925 / https://www.stigviewer.com/stig/windows_server_2019/2020-06-15/finding/V-93269
2016: https://www.stigviewer.com/stig/microsoft_windows_server_2016/2021-09-29/finding/V-224956 / https://www.stigviewer.com/stig/windows_server_2016/2020-06-16/finding/V-73589
Desktop:
W11: https://www.stigviewer.com/stig/microsoft_windows_11/2022-06-24/finding/V-253413
W10: https://www.stigviewer.com/stig/microsoft_windows_10/2022-04-08/finding/V-220859 / https://www.stigviewer.com/stig/windows_10/2021-08-18/finding/V-220859
NIST 800-53: IA-5(13)
NIST 800-171 Rev 3 FPD: 3.5.5.a
NIST 800-171 A rec3 IPD : A.03.01.01.c[02], A.03.01.01.c[03], A.03.01.01.d[01], A.03.01.01.d[02]
CSCv6|16.5
NIST 800-53: AC-11
CIS CSCv7: 16.11