STIGQter STIGQter: STIG Summary: Microsoft Windows 11 Security Technical Implementation Guide Version: 2 Release: 8 Benchmark Date: 01 Jul 2026:

Standard local user accounts must not exist on a system in a domain.

DISA Rule

SV-253272r1210286_rule

Vulnerability Number

V-253272

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

WN11-00-000085

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Limit local user accounts on domain-joined systems. Remove any unauthorized local accounts.

Check Contents

Run "Computer Management".

Navigate to System Tools >> Local Users and Groups >> Users.

If local users other than the accounts listed below exist on a workstation in a domain, this is a finding.

The accounts listed assumes a system is joined to a domain and thus (per best practice), the local default accounts have been disabled.

For standalone or nondomain-joined systems, this is Not Applicable.

Built-in administrator account (Disabled, SID ending in 500)
Built-in guest account (Disabled, SID ending in 501)
Built-in DefaultAccount (Disabled, SID ending in 503)
Built-in defaultuser0 (Disabled, *SID unique per workstation)
Built-in WDAGUtilityAccount (Disabled, SID ending in 504)
Local administrator account(s)
* Note that the SID for defaultuser0 is machine-specific and immutable (cannot be changed). It will differ per Windows installation.

All of the built-in accounts may not exist on a system, depending on the Windows 11 version.

Vulnerability Number

V-253272

Documentable

False

Rule Version

WN11-00-000085

Severity Override Guidance

Run "Computer Management".

Navigate to System Tools >> Local Users and Groups >> Users.

If local users other than the accounts listed below exist on a workstation in a domain, this is a finding.

The accounts listed assumes a system is joined to a domain and thus (per best practice), the local default accounts have been disabled.

For standalone or nondomain-joined systems, this is Not Applicable.

Built-in administrator account (Disabled, SID ending in 500)
Built-in guest account (Disabled, SID ending in 501)
Built-in DefaultAccount (Disabled, SID ending in 503)
Built-in defaultuser0 (Disabled, *SID unique per workstation)
Built-in WDAGUtilityAccount (Disabled, SID ending in 504)
Local administrator account(s)
* Note that the SID for defaultuser0 is machine-specific and immutable (cannot be changed). It will differ per Windows installation.

All of the built-in accounts may not exist on a system, depending on the Windows 11 version.

Check Content Reference

M

Target Key

5471