Forced logoff not enabled for account with expired time |
---|
Risk Level: | Low | Check or Attack Name: Forced Logoff |
---|---|---|
Platforms: | Windows NT | |
Description: | A user whose logon hours have expired is not forced to log off. If this option is not enabled, users will not be forced to log out once their allowed login hours expire. This situation allows a user to maintain open connections. If your security policy restricts logon hours, you may want to enable this feature. |
|
Remedy: | Enable forced logoffs. From a Primary Domain Controller (PDC), enable logoffs:
Note: If logon hours are not also restricted, this setting will have no effect. |
|
References: |
Know Your Risks |