9.1.1.15. Disable Inactive Accounts

Local accounts are disabled 35 days after their password expires. This is enforced using the ‘inactive’ value in the /etc/default/useradd file.

References: AC-2 (3) : DISABLE INACTIVE ACCOUNTS