3.4 Ensure 'Minimum password length' is set to '4' or more

Information

This policy setting is used to specify a minimum password length for the device.

Rationale:

Types of password attacks include dictionary attacks that use common words and phrases, and brute force attacks that use character combinations. Attackers also sometimes try to obtain an account database so they can use tools to discover accounts and passwords.

Impact:

None - This is the default behavior.

Note: This is a mobile device management setting. Use caution when applying these settings as they could have adverse effects depending on the environment, and internal policies around bring your own device (BYOD). These policies could affect a user's BYOD.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MobileDeviceMailboxPolicy 'Profile' -MinPasswordLength 4

OR

Perform the following actions:

Launch the EAC (Exchange Administrative Center).

Go to 'Mobile' on the left and click on the 'Mobile device mailbox policies' tab.

Double-click the policy you wish to modify and go to the 'Security' settings.

Ensure the Minimum password length box is checked and change the value to 4 and click Save

Default Value:

4

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Windows

Control ID: 7a7079799e6ee59ae7079ac814f82a32efb75379238fd730f01f2c9e12ab1d38