Accounts: The computer account password must not be prevented from being reset

e0059e71-73e6-4c05-9f59-b224041025ea

Computer account passwords are changed automatically on a regular basis. Disabling automatic password changes can make the system more vulnerable to malicious access. Frequent password changes can be a significant safeguard for the system. A new password for the computer account will be generated every 30 days.

Remediation

To fix this configure the policy value for
Computer Configuration
|_ Windows Settings
|_ Security Settings
|_ Local Policies
|_ Security Options
|_ "Domain member: Disable machine account password changes" to "Disabled".

STIG
Server:
2022: https://system32.eventsentry.com/stig/viewer/V-254453
2019: https://system32.eventsentry.com/stig/viewer/V-205815

Desktop:
W11: https://system32.eventsentry.com/stig/viewer/V-253441
W10: https://system32.eventsentry.com/stig/viewer/V-220917

NIST 800-53: CM-6b.
CAT: III
CCI:CCI-000366
PCI-DSS v4: 10.7, 10.7.1, 10.7.2, 10.7.3
Rule-ID:V-29029r1_rule
STIG-ID:3.044, Vuln-ID|V-1165
MITRE Att&ck: T1098