Minimum password length

Information

Minimum password length

This security setting determines the least number of characters that a password for a user account may contain. You can set a value of between 1 and 14 characters, or you can establish that no password is required by setting the number of characters to 0.

Default:

7 on domain controllers.
0 on stand-alone servers.

Note: By default, member computers follow the configuration of their domain controllers.

Solution

Policy Path: Password Policy
Policy Setting Name: Minimum password length

See Also

https://blogs.technet.microsoft.com/secguide/2018/04/30/security-baseline-for-windows-10-april-2018-update-v1803-final/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(a), CSCv6|5.7, CSCv6|16.2, CSCv6|16.5

Plugin: Windows

Control ID: 30621fcf6ea4d492c2d9c243784b39cecdc07fbcb205adba147793a615489a20