User accounts that have been inactive for over a given period of time can be automatically disabled. It is recommended that accounts that are inactive for 35 or more days be disabled.
Rationale:
Inactive accounts pose a threat to system security since the users are not logging in to notice failed login attempts or other anomalies.
[30_days]
# useradd -D -f 35
oval:org.secpod.oval:def:92260
oval:org.secpod.oval:def:85145
oval:org.secpod.oval:def:87302
oval:org.secpod.oval:def:65953
SCAP Repo OVAL Definition
2023-08-23