Skip to content

Windows Server 2022 Smart Card removal option must be configured to Force Logoff or Lock Workstation.

An XCCDF Rule

Description

Unattended systems are susceptible to unauthorized use and must be locked. Configuring a system to lock when a smart card is removed will ensure the system is inaccessible when unattended.

ID
SV-254459r991589_rule
Version
WN22-SO-000150
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Interactive logon: Smart card removal behavior to "Lock Workstation" or "Force Logoff".