Local Security Policy lets administrators set a computer-wide password policy for local Windows accounts: require complex passwords, set a minimum length, prevent reuse of recent passwords, and require periodic password changes. This procedure applies to Windows 11 and Windows 10 Pro, Enterprise, and Education editions, where the Local Security Policy console is available. Windows Home does not include that console; it can still view and set several numeric password-policy values with the built-in net accounts command, but it cannot use that command to enable the Windows complexity rule.

These settings apply to local accounts on the PC, including local administrator accounts. They do not change the password requirements of a Microsoft account, an organization-managed Microsoft Entra account, or a domain account. If the computer is joined to an Active Directory domain or managed by an organization, centrally applied policy can override local settings. In that case, confirm the intended policy with the IT administrator before making local changes.

A desktop monitor displays password security settings beside a glowing shield and locked password field.Check the edition, account type, and current policy​

Windows 11 Settings on the System > About page showing Device specifications, Windows specifications and edition

You must be signed in with an account that has administrator rights to change Local Security Policy settings.

Quick walkthrough

4bac7528a9eb-exact.webp
  • Open Settings.
  • Use the applicable path:
  • Windows 11: Select System > About.
  • Windows 10: Select System > About.
  • Under Windows specifications, check the Edition entry.
  • Continue with Local Security Policy if it says Pro, Enterprise, or Education.
  • If it says Home, skip to the Windows Home section later in this guide.
  • Confirm that the accounts you intend to protect are local accounts:
  • Windows 11: Go to Settings > Accounts > Other users.
  • Windows 10: Go to Settings > Accounts > Family & other users.

A local account is normally listed by its local user name rather than an email address. Password rules configured here are computer-wide: Windows does not provide separate Local Security Policy password rules for individual local users.

  • Record the current password-policy values before changing anything. Open Windows Terminal (Admin), Command Prompt (Admin), or PowerShell (Admin), then run:
    net accounts
    The output includes the current minimum and maximum password age, minimum password length, and password-history length. Keep this output so you can restore the previous numeric settings if a policy causes an unexpected compatibility problem.
    net accounts does not show whether Password must meet complexity requirements is enabled. You must check that setting in Local Security Policy.
Shows the Accounts page for Other users, including the section and controls to add or manage another user account on the PC.
Warning: Tightening a password policy does not automatically change existing passwords, but it affects the next password creation or password change. Before enabling expiration or complexity requirements, make sure every local account owner can create and retain a compliant password. Keep at least one known, working local administrator account available so that you do not lose administrative access after a password change.

Open Password Policy in Local Security Policy​

Local Security Policy with the Security Settings tree (Account Policies, Local Policies).
  • Press Windows + R to open the Run dialog.
  • Type:
    secpol.msc
  • Select OK.
  • If User Account Control asks for permission, select Yes.
  • In the left pane, expand:
    Code:
    Security Settings
    > Account Policies
    > Password Policy
  • The right pane displays the local password-policy settings:
  • Enforce password history
  • Maximum password age
  • Minimum password age
  • Minimum password length
  • Minimum password length audit
  • Password must meet complexity requirements
  • Store passwords using reversible encryption

For the settings covered below, open a policy by double-clicking it, enter or select the desired value, then select Apply and OK. Changes take effect without restarting Windows.

Do not enable Store passwords using reversible encryption as part of a stronger-password configuration. Microsoft describes reversible password storage as effectively equivalent to storing plaintext passwords. It is only intended for specific legacy authentication scenarios that require it.

Set a stronger minimum password length​

A longer password or passphrase is generally more useful than forcing complicated character substitutions alone. In the Local Security Policy editor, the standard Minimum password length policy supports a value from 0 through 14 characters.

  • Double-click Minimum password length.
  • Enter the minimum number of characters required for future local-account passwords.
  • Select Apply, then OK.

For a shared PC or an administrator-managed local account, set at least 8 characters as a baseline. A longer memorable passphrase is preferable where users can manage it safely. Avoid setting this policy to 0; that permits accounts without a password.

The policy is enforced the next time a local user creates or changes a password. It does not invalidate a current password simply because that password is shorter than the new minimum.

Require Windows password complexity​

Windows can apply its built-in complexity rule to local account passwords. This setting is a fixed rule, not a custom character-pattern editor.

  • Double-click Password must meet complexity requirements.
  • Select Enabled.
  • Select Apply, then OK.

When enabled, a new or changed password must meet these requirements:

  • It must not contain the user’s account name.
  • It must not contain substantial consecutive portions of the user’s full name.
  • It must be at least six characters long.
  • It must contain characters from at least three of these four categories:
  • Uppercase English letters
  • Lowercase English letters
  • Numbers
  • Non-alphanumeric characters, such as punctuation or symbols

The complexity policy does not replace the minimum-length policy. For example, complexity alone still permits a six-character password if it meets the category rule. Set Minimum password length separately to establish the length you require.

This rule is evaluated only when a password is set or changed. It does not silently convert or reject an existing password after you enable the policy.

Prevent users from reusing old passwords​

Password history stops a local user from alternating between a small set of familiar passwords.

  • Double-click Enforce password history.
  • Enter the number of previous passwords Windows must remember.
  • Select Apply, then OK.

The local security policy interface supports values from 0 through 24. A value of 0 disables password history. For stronger reuse protection, use a meaningful history value such as 12 or 24.

Password history works best with a nonzero minimum password age. Otherwise, a user can change passwords repeatedly in a short period until the history list is exhausted, then select an old password again.

Set the minimum time before a password can be changed again​

This setting prevents rapid password cycling intended to defeat the password-history rule.

  • Double-click Minimum password age.
  • Enter the number of days a password must be used before its owner can change it again.
  • Select Apply, then OK.

A value of 0 allows immediate password changes. Set it to 1 day if you are enforcing password history and want that history to be meaningful.

Warning: A nonzero minimum password age can affect newly provisioned accounts. If an administrator sets a temporary password and expects the user to replace it immediately, a minimum-age policy may prevent that change unless the account is configured to require a password change at next sign-in. Plan account provisioning before setting a restrictive minimum age.

The minimum password age must be lower than the maximum password age when password expiration is enabled.

Require periodic password changes—or deliberately disable expiration​

The Maximum password age policy controls how long a local password remains valid before Windows requires a change.

  • Double-click Maximum password age.
  • Choose the required value:
  • Enter a number of days to require expiration.
  • Enter 0 to specify that passwords do not expire.
  • Select Apply, then OK.

The supported expiration range is 1 through 999 days when expiration is enabled. If you configure an expiration period, make sure it is greater than the Minimum password age value.

For example, an organization might use a maximum age of 90 days and a minimum age of 1 day, paired with password history and complexity. However, forced periodic password changes can lead users to make predictable changes if they are not also using unique, strong passwords. Choose an expiration period that fits the PC’s risk level and the organization’s broader account-management practices.

Remember that this policy covers local Windows accounts only. It does not impose a password-expiration period on a Microsoft account or an organization’s cloud identity.

Verify the policy was applied​

After closing Local Security Policy, open an elevated command window and run:

net accounts

Check these entries against the values you selected:

Code:
Minimum password age (days)
Maximum password age (days)
Minimum password length
Length of password history maintained

To verify complexity, return to:

Code:
Security Settings
> Account Policies
> Password Policy
> Password must meet complexity requirements

Open the policy and confirm that it is set to Enabled.

For a practical test, use a noncritical local test account rather than the only administrator account on the PC.

  • Sign in to the test account, or use a separate administrator account to initiate its password change.
  • Attempt to set a password that is shorter than the configured minimum or does not satisfy complexity.
  • Windows should reject the password and require one that meets the policy.
  • Set a compliant password and sign in with it successfully.

Do not repeatedly change passwords to test history if you have set a minimum password age. That policy is designed to block rapid changes.

Windows Home: safe alternatives for viewing and setting supported values​

Windows Home normally does not include the Local Security Policy console, so secpol.msc will not provide this interface. Do not download unofficial policy-editor installers or use registry scripts from unknown sources merely to expose a missing console. Those methods can alter security settings without giving you a supported management path.

Windows Home can safely display the numeric local-account policy with:

net accounts

Run the command from an elevated Windows Terminal, Command Prompt, or PowerShell window to change the numeric policies. For example:

net accounts /minpwlen:8 /minpwage:1 /maxpwage:90 /uniquepw:12

This configures:

  • A minimum password length of 8 characters
  • A minimum password age of 1 day
  • A maximum password age of 90 days
  • A history of 12 passwords

To disable password expiration, use:

net accounts /maxpwage:unlimited

Then verify the result with:

net accounts

The net accounts command supports the length, age, and history settings, but it does not provide a switch to turn the Windows Password must meet complexity requirements policy on or off. On Windows Home, use a longer unique passphrase for each local account and verify the numeric policy with net accounts rather than attempting unsupported Local Security Policy workarounds.

Troubleshoot policy conflicts and recover from a bad setting​

secpol.msc cannot be found​

This usually means the device is running Windows Home or the management console is unavailable on that installation.

  • Confirm the edition under Settings > System > About.
  • On Windows Home, use net accounts for the supported numeric controls.
  • Do not use unofficial downloads that claim to add Local Security Policy to Home.

A new password is rejected even though it is long enough​

Check the complexity rule. With Password must meet complexity requirements enabled, a password also needs characters from at least three of four categories and must not contain the account name or prohibited portions of the user’s full name.

Use a longer passphrase that avoids the account holder’s name and includes the required character categories. Do not disable complexity solely to accommodate a weak password unless you have a documented compatibility need.

A user cannot change a password immediately after it was assigned​

Check Minimum password age. If it is set to 1 or more, Windows blocks normal password changes until that number of days has passed.

If this is an account-provisioning issue, have an administrator set the intended password and use the proper account-management process for requiring a password change at next sign-in. If the minimum-age setting was inappropriate for the PC, reduce it temporarily or restore it to 0, then reapply the intended policy after the account transition is complete.

Passwords do not appear to expire as expected​

First verify Maximum password age with:

net accounts

If the maximum age is Unlimited or 0, expiration is disabled. If the PC is domain-joined or organization-managed, a domain or device-management policy can take precedence over the local policy. Do not try to override an organization’s policy locally; contact the administrator responsible for identity management.

Also check whether the affected local account has been individually configured so that its password does not expire. A per-account exception can prevent the expected expiration behavior.

Restore the prior numeric policy​

If the new rules create a problem, open the saved net accounts output from before the change and restore the original values with the corresponding switches. For example:

net accounts /minpwlen:6 /minpwage:0 /maxpwage:unlimited /uniquepw:0

Replace the example values with the values you recorded from the computer before making changes. For complexity, reopen Local Security Policy, select Password must meet complexity requirements, and return it to its prior Enabled or Disabled state.

 

Last edited by a moderator: