Build password requirements for your organization by configuring password length, complexity and character requirements.
Choose a starting point or configure the requirements yourself.
Presets provide a convenient starting configuration and can be adjusted at any time.
Choose which character types passwords must contain.
Optionally require more than one character from each selected type.
A readable summary based on your selected requirements.
Things to consider before applying this configuration.
Looking beyond password policies? Assess your organization's PAM readiness.
Password requirements should reflect your organization's security needs, authentication controls, account types and the systems where passwords will be used. Review your policy before applying it in production.
Password requirements should make credentials harder to compromise without encouraging predictable behaviour or unnecessary complexity.
Longer passwords increase the available search space and can provide greater resistance to password guessing attacks.
Privileged accounts and sensitive systems may warrant different password requirements from lower-risk accounts and applications.
Clearly defined policies make it easier to apply consistent password requirements across users, accounts and systems.
Common questions about creating and managing password policies.
A password policy defines requirements for how passwords should be created and managed. Requirements can include minimum length, character types and other controls appropriate to the accounts and systems being protected.
Password length should reflect the security requirements of the account and system. Longer passwords generally provide greater resistance to password guessing attacks, provided they are not based on predictable patterns.
Not necessarily. Different systems may have different technical limitations and security requirements. Privileged and high-value accounts may also warrant different requirements from standard user accounts.
Yes. Passwordstate supports multiple configurable Password Strength Policies so different systems, accounts and security contexts can use different password requirements.