Domain Password History Requirements
Password must meet complexity.
Domain password history requirements. 60 or fewer days. The value must be between 0 and 24 passwords. By default in every installation of active directory the default domain policy establishes the domain password policy for all users configured and stored in active directory that is.
By default in server 2016 passwords must meet the following minimum requirements. The default minimum is one day both for windows and the security baselines. Store passwords using reversible encryption.
The maximum defaults to 42 days for windows and until recently 60 days in the security baselines. Enforce password history policy the enforce password history policy will set how often an old password can be reused. Try to expire the passwords between major business cycles to prevent work loss.
Passwords must not contain the user s account name or parts of the user s full name that exceed two consecutive characters. The maximum is the number of days after which users must change their password. This policy will discourage users from reusing a previous password thus preventing them from alternating between several common passwords.
Set maximum password age to expire passwords between 60 and 90 days. The minimum age is the number of days before users are allowed to change a password. Passwords must be at least seven characters in length.
Set enforce password history to 24. This security setting determines the number of unique new passwords that have to be associated with a user account before an old password can be reused. Default domain policy password policy.