Interactive logon Machine inactivity limit - Windows 10 (2024)

  • Article

Applies to

  • Windows11
  • Windows10

Describes the best practices, location, values, management, and security considerations for the Interactive logon: Machine inactivity limit security policy setting.

Reference

Beginning with Windows Server 2012 and Windows 8, Windows detects user-input inactivity of a sign-in (logon) session by using the security policy setting Interactive logon: Machine inactivity limit. If the amount of inactive time exceeds the inactivity limit set by this policy, then the user's session locks by invoking the screen saver (screen saver should be active on the destination machine). You can activate the screen saver by enabling the Group Policy User Configuration\Administrative Templates\Control Panel\Personalization\Enable screen saver. This policy setting allows you to control the locking time by using Group Policy.

Note

If the Interactive logon: Machine inactivity limit security policy setting is configured, the device locks not only when inactive time exceeds the inactivity limit, but also when the screensaver activates or when the display turns off because of power settings.

Possible values

The automatic lock of the device is set in elapsed seconds of inactivity, which can range from zero (0) to 599,940 seconds (166.65 hours).

If Machine will be locked after is set to zero (0) or has no value (blank), the policy setting is disabled and a user sign-in session is never locked after any inactivity.

Best practices

Set the time for elapsed user-input inactivity based on the device's usage and location requirements. For example, if the device or device is in a public area, you might want to have the device automatically lock after a short period of inactivity to prevent unauthorized access. However, if the device is used by an individual or group of trusted individuals, such as in a restricted manufacturing area, automatically locking the device might hinder productivity.

Location

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options (While creating and linking group policy on server)

Default values

The following table lists the actual and effective default values for this policy. Default values are also listed on the policy's property page.

Server type or GPODefault value
Default Domain PolicyNot defined
Default Domain Controller PolicyNot defined
Stand-Alone Server Default SettingsDisabled
DC Effective Default SettingsDisabled
Member Server Effective Default SettingsDisabled
Client Computer Effective Default SettingsDisabled

Policy management

This section describes features and tools that are available to help you manage this policy.

Restart requirement

Restart is required for changes to this policy to become effective when they're saved locally or distributed through Group Policy.

Group Policy

Because this policy setting was introduced in Windows Server 2012 and Windows 8, it can only be set locally on those computers that contain this policy setting, but it can be set and distributed through Group Policy to any computer running the Windows operating system that supports Group Policy.

Security considerations

This section describes how an attacker might exploit a feature or its configuration, how to implement the countermeasure, and the possible negative consequences of countermeasure implementation.

Vulnerability

This policy setting helps you prevent unauthorized access to devices under your control when the currently signed-in user leaves without deliberately locking the desktop. In versions earlier than Windows Server 2012 and Windows 8, the desktop-locking mechanism was set on individual computers in Personalization in Control Panel.

Countermeasure

Set the time for elapsed user-input inactivity time by using the security policy setting Interactive logon: Machine inactivity limit based on the device's usage and location requirements.

Potential impact

This security policy setting can limit unauthorized access to unsecured computers; however, that requirement must be balanced with the productivity requirements of the intended user.

Interactive logon Machine inactivity limit - Windows 10 (2024)
Top Articles
What is a Bill of Lading? | Shipware
STALE BILL OF LADING What does it mean?
Methstreams Boxing Stream
Overnight Cleaner Jobs
Samsung 9C8
Https Www E Access Att Com Myworklife
Best Private Elementary Schools In Virginia
Ohiohealth Esource Employee Login
Jscc Jweb
Capitulo 2B Answers Page 40
Miami Valley Hospital Central Scheduling
The Weather Channel Facebook
Voyeuragency
Animal Eye Clinic Huntersville Nc
Restaurants Near Paramount Theater Cedar Rapids
Google Feud Unblocked 6969
Les Rainwater Auto Sales
Rachel Griffin Bikini
Bj Alex Mangabuddy
The Pretty Kitty Tanglewood
St. Petersburg, FL - Bombay. Meet Malia a Pet for Adoption - AdoptaPet.com
Nhl Tankathon Mock Draft
Rural King Credit Card Minimum Credit Score
eHerkenning (eID) | KPN Zakelijk
Www Craigslist Madison Wi
Powerschool Mcvsd
Amelia Chase Bank Murder
Watertown Ford Quick Lane
Abga Gestation Calculator
Craigslist Scottsdale Arizona Cars
What Is The Lineup For Nascar Race Today
Vlocity Clm
Mrstryst
15 Downer Way, Crosswicks, NJ 08515 - MLS NJBL2072416 - Coldwell Banker
Ixlggusd
Japanese Pokémon Cards vs English Pokémon Cards
Lil Durk's Brother DThang Killed in Harvey, Illinois, ME Confirms
Gwen Stacy Rule 4
KITCHENAID Tilt-Head Stand Mixer Set 4.8L (Blue) + Balmuda The Pot (White) 5KSM175PSEIC | 31.33% Off | Central Online
Rs3 Bis Perks
Electronic Music Duo Daft Punk Announces Split After Nearly 3 Decades
Tunica Inmate Roster Release
Wilson Tire And Auto Service Gambrills Photos
[Teen Titans] Starfire In Heat - Chapter 1 - Umbrelloid - Teen Titans
Blue Beetle Showtimes Near Regal Evergreen Parkway & Rpx
Uno Grade Scale
Congressional hopeful Aisha Mills sees district as an economical model
Arnold Swansinger Family
Ocean County Mugshots
Latest Posts
Article information

Author: Madonna Wisozk

Last Updated:

Views: 5831

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Madonna Wisozk

Birthday: 2001-02-23

Address: 656 Gerhold Summit, Sidneyberg, FL 78179-2512

Phone: +6742282696652

Job: Customer Banking Liaison

Hobby: Flower arranging, Yo-yoing, Tai chi, Rowing, Macrame, Urban exploration, Knife making

Introduction: My name is Madonna Wisozk, I am a attractive, healthy, thoughtful, faithful, open, vivacious, zany person who loves writing and wants to share my knowledge and understanding with you.