Skip to content

Ensure all users last password change date is in the past

An XCCDF Rule

Description

All users should have a password change date in the past.

warning alert: Warning

Automatic remediation is not available, in order to avoid any system disruption.

Rationale

If a user recorded password change date is in the future then they could bypass any set password expiration.

ID
xccdf_org.ssgproject.content_rule_accounts_password_last_change_is_in_past
Severity
Medium
References
Updated