STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288137

CAT I (High)

Local accounts must be removed after multifactor authentication (MFA) is configured. It is permissible for an emergency ("break glass") or service account to remain if absolutely required by the application. In this case, the associated complexity requirements apply.

Rule ID

SV-288137r1252644_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-000765CCI-000766CCI-004046CCI-000778CCI-001953CCI-001954CCI-002009CCI-002010CCI-004046CCI-004047

Discussion

Without the use of MFA, the ease of access to privileged functions is greatly increased. MFA requires the use of two or more factors to achieve authentication. Factors include: (i) Something a user knows (e.g., password/PIN); (ii) Something a user has (e.g., cryptographic identification device, token); or (iii) Something a user is (e.g., biometric). The current DoW multifactor solution is the common access card (CAC). Other DoW or authorizing official (AO)-approved solutions may be implemented. To ensure MFA is used, access to local accounts must be removed.

Check Content

Navigate to the local account configuration function within the application.

Verify no local accounts exist. Otherwise, this is a finding.

If a break glass or service account remains, this must be documented and approved by the AO. Otherwise, this is a finding.

Fix Text

Navigate to the local account configuration function within the application and remove all local accounts.

For break glass or service accounts, apply the appropriate password complexity per policy.