PolicyCurrent SettingDescription
Enforce password history5 passwords rememberedThis security setting determines the number of unique new passwords that have to be associated with a user account before an old password can be reused.
Maximum password age30 daysThis security setting determines the period of time (in days) that a password can be used before the system requires the user to change it.
Minimum password age1 dayThis security setting determines the period of time (in days) that a password must be used before the user can change it.
Minimum password length8 charactersThis security setting determines the least number of characters that a password for a user account may contain.
Password must meet complexity requirementsEnableThis security setting determines whether passwords must meet complexity requirements.
Passwords must meet the following minimum requirements:
  1. Not contain the user's account name or parts of the user's full name that exceed two consecutive characters
  2. Be at least six characters in length
  3. Contain characters from three of the following four categories:
    • English uppercase characters (A through Z)
    • English lowercase characters (a through z)
    • Base 10 digits (0 through 9)
    • Non-alphabetic characters (for example, !, $, #, %)
Complexity requirements are enforced when passwords are changed or created.