Information
This policy setting configures the number of complex element types (uppercase and lowercase letters, numbers, and punctuation) required for PIN or password.
The recommended state for this setting is: Digits and lowercase letters are required
Note: The enforcement of policies for Microsoft accounts happens on the server, and the server requires a password length of 8 and a complexity of 2 A complexity value of 3 or 4 is unsupported and setting this value on the server makes Microsoft accounts non-compliant. However, configuring this setting to 2 will force the value of 3 for Local accounts.
Passwords should contain complexity to ensure they are not easily guessed or brute-forced by a malicious actor.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Digits lowercase letters and uppercase letters are required :
Device Lock\Device Password Enabled: Alphanumeric Device Password Required: Min Device Password Complex Characters
Note: As of March 20, 2025, this setting is nested under
Alphanumeric Device Password Required
and may not fully appear in Settings Catalog unless unchecked and re-checked in the settings picker.
Impact:
If an organization is using Windows Hello for Business the the Device Lock password settings can impact PIN polices if those policies are not first defined elsewhere. Windows will follow the Windows Hello for Business policies for PINs if this key exists: HKLM\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\Device\Policies Otherwise, it will follow Device Lock policies.