Skip to Content

Password Policies

Configure password complexity, expiration, and protection policies for your Microsoft 365 organization.

Password Settings

SettingRecommended
Minimum length14 characters
ComplexityNot required (use length instead)
ExpirationNo expiration (with MFA)
Banned passwordsCustom banned password list
Smart lockoutEnabled

Azure AD Password Protection

  • Global banned password list — Microsoft-maintained common password list
  • Custom banned password list — Organization-specific terms to block
  • Smart lockout — Lock accounts after failed attempts from same IP

Self-Service Password Reset

  • Enabled — Allow users to reset their own passwords
  • Methods required — Number of verification methods needed
  • Registration — Require SSPR registration at sign-in

API Reference

  • GET /api/security/password-policies — Get policies
  • PUT /api/security/password-policies — Update policies
Last updated on