The operating system must not allow an unattended or automatic logon to the system.

STIG ID: SRG-OS-000480-GPOS-00229  |  SRG: SRG-OS-000480 | Severity: high |  CCI: CCI-000366

Vulnerability Discussion

Failure to restrict system access to authenticated users negatively impacts operating system security.

Check

If the operating system provides a public access service, such as a kiosk, this is not applicable. Verify the operating system does not allow an unattended or automatic logon to the system. If it does, this is a finding. Automatic logon as an authorized user allows access to any user with physical access to the operating system.

Fix

If the operating system provides a public access service, such as a kiosk, this is not applicable. Configure the operating system to not allow an unattended or automatic logon to the system. Automatic logon as an authorized user allows access to any user with physical access to the operating system.