STIGQter STIGQter: STIG Summary: Microsoft Windows PAW Security Technical Implementation Guide Version: 3 Release: 3 Benchmark Date: 01 Apr 2026:

The Windows PAW must be configured to enforce two-factor authentication and use Active Directory for authentication management.

DISA Rule

SV-243457r1015765_rule

Vulnerability Number

V-243457

Group Title

SRG-OS-000107-GPOS-00054

Rule Version

WPAW-00-001600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In Active Directory, configure group policy to enable either smart card or another DOD-approved two-factor authentication method for all PAWs.

- Go to Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options.
- Set "Interactive logon: Require Windows Hello for Business or smart card" to "Enabled".

Check Contents

Review the configuration on the PAW.

Verify group policy is configured to enable either smart card or another DOD-approved two-factor authentication method for site PAWs.

- In Active Directory, go to Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options.
- Verify "Interactive logon: Require Windows Hello for Business or smart card" is set to "Enabled".

If group policy is not configured to enable either smart card or another DOD-approved two-factor authentication method, this is a finding.

Vulnerability Number

V-243457

Documentable

False

Rule Version

WPAW-00-001600

Severity Override Guidance

Review the configuration on the PAW.

Verify group policy is configured to enable either smart card or another DOD-approved two-factor authentication method for site PAWs.

- In Active Directory, go to Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options.
- Verify "Interactive logon: Require Windows Hello for Business or smart card" is set to "Enabled".

If group policy is not configured to enable either smart card or another DOD-approved two-factor authentication method, this is a finding.

Check Content Reference

M

Target Key

5405