Remote Desktop Services: Idle session time limit

a06670b6-460f-45ae-93ef-02d41f52d45e

This setting controls how long a session may be idle before it is automatically disconnected from the server. Users should log off if they plan on being away from their terminals for extended periods of time. Idle sessions should be disconnected after 15 minutes.

Remediation

Configure the policy value for:
Computer Configuration
|_ Administrative Templates
|_ Windows Components
|_ Remote Desktop Services
|_ Remote Desktop Session Host
|_ Session Time Limits
|_ Set time limit for active but idle Remote Desktop Services sessions = Enabled
and “Idle session limit” = 15 minutes or less, excluding 0 which equates to “Never”.

Remote Desktop Services Idle session time should be enabled and configured for 15 minutes or less.

Stig: Server:
2016: https://www.stigviewer.com/stig/windows_server_2016/2017-05-18/finding/V-73659

Desktop:
https://www.stigviewer.com/stig/windows_7/2012-08-22/finding/V-3458

More info: https://www.ryadel.com/en/remote-desktop-session-time-limit-how-to-set-idle-timeout-in-windows-server-2012/

NIST 800-171: SC10,SC23
NIST 800-53: AC-12
MITRE Att&ck: T1021.001, T1563.002 Mitigations: M1028