Minimum password length

Information

Minimum password length

This security setting determines the least number of characters that a password for a user account may contain. You can set a value of between 1 and 14 characters, or you can establish that no password is required by setting the number of characters to 0.

Default:

7 on domain controllers.
0 on stand-alone servers.

Note: By default, member computers follow the configuration of their domain controllers.

Solution

Policy Path: Account Policies\Password Policy
Policy Name: Minimum password length

See Also

https://blogs.technet.microsoft.com/secguide/2015/11/13/security-baseline-for-windows-10-build-10240-final/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(a), CSCv6|5.7, CSCv6|16.2, CSCv6|16.5

Plugin: Windows

Control ID: 587bdc9b29b357eae4349ec9e5e0e10eed1e5d96c37dba48924999b6bbe57ad2