Setting a Password Policy
The password policy sets the rules a password must meet before the platform will accept it: how long it must be, whether it needs particular kinds of character, and which obvious choices are refused. It applies to local accounts, the ones whose password the platform holds. People who sign in through Active Directory, Azure AD, SAML or a social provider are governed by that provider's rules instead.
Where to find it
Architect Panel → Configuration:
- Site Settings — the Password Policy group, with its own Save Settings button
Architect Panel → Security:
- Security Check-up — the Password policy section, which shows the policy in force and assesses it
The settings
- Minimum Password Length: the fewest characters a password may have. Ships at 8. Counted in characters, so an accented passphrase is measured fairly.
- Maximum Password Length: a ceiling, so an enormous input cannot be used to tie up the server. Ships at 128. Do not raise it above 128: the platform's password hashing refuses anything longer, so a higher value would accept a password that then fails to save.
- Require A Capital Letter, Require A Lower-case Letter, Require A Number and Require A Symbol: composition rules. All four ship off.
- Block Common Passwords: refuses a short list of the passwords people choose when they do not care, such as password or 12345678. Ships on. It is a short list by design, not a list of every breached password, so do not describe it as one in an audit.
- Block Passwords Containing The Username: refuses a password that contains the username, checked without regard to case and only when the username is at least four characters long. Ships on.
- Previous Passwords To Remember and Password Expires After (Days): reuse and expiry, covered in Password Expiry and Reuse. Both ship at 0, which means off.
The shipped values match what the platform allowed before the policy existed, so switching to a release with these settings changes nobody's experience until you change them.
Setting a policy
- Open Site Settings and find the Password Policy group.
- Set Minimum Password Length. Twelve is the figure Cyber Essentials expects when you have no multi-factor authentication; eight is accepted alongside multi-factor authentication or common-password blocking.
- Leave Block Common Passwords and Block Passwords Containing The Username on.
- Switch on composition rules only if a contract or procurement requires them.
- Click Save Settings for the group.
- Open Security Check-up and confirm the Password policy section shows the new values.
- Change your own password to one that breaks a rule, and check the message you are shown.
Why length rather than composition
The NCSC and NIST both advise raising the minimum length rather than demanding capitals and symbols. Composition rules push people towards predictable patterns, such as a capital at the start and a number and symbol at the end, and away from the long passphrases that are genuinely hard to guess. The Security Check-up says so in its note on composition rules, and an assessor will usually accept a length-only policy with that reasoning.
Where it is enforced
Every place a local password is set: a person changing their own password on their account page, self-registration, the administrator's user editor, the forgotten-password flow, vendor sign-up, the installer and any form with a password field. Restoring an old version of an account from its audit history cannot bring back an old password. The rules apply when a password is set or changed; existing passwords are not re-checked, so a stricter minimum takes effect as people change their passwords.
Somebody changing their own password must also enter their current one, so a person who finds an unlocked, signed-in browser cannot take the account over.
What people see
A refused password produces one message saying what is wrong and nothing else, for example "Your password must be at least 12 characters long.", "Your password must contain a number.", "That password is too easily guessed. Please choose another." or "Your password must not contain your username."
What goes wrong
- The new rule is not applied. Check you clicked Save Settings for the Password Policy group, not another group on the same screen.
- Site Settings shows a configuration inconsistency for a Password Policy setting. The setting is missing from the server's configuration file. Your hosting administrator needs to add it before the group can be saved.
- Single sign-on users are not affected. That is correct: their password is held by their identity provider.
Worked example
A training provider's Security Check-up shows Minimum length: 8 characters, assessed as Review, with no multi-factor authentication in force yet. The administrator raises the minimum to 12, leaves composition rules off, keeps both blocking rules on and saves the group. The check-up now shows OK for length. A test change to "Spring2026" is refused as too short, and the help desk's script is updated with the new message.
Recommendations
- Raise the minimum length before reaching for composition rules.
- Keep both blocking rules on.
- Never set the maximum above 128.
- Tell users before tightening the policy, and say what the new rule is.
- Pair the policy with a second factor; a good password is still a single factor.