Skip to main content

Characters (Complexity) rule

The Complexity rule rejects passwords that don't contain characters from a variety of character sets. A complex password takes longer to brute-force crack than a simple password of the same length.

Character Complexity Rule

Select the Characters (Complexity) checkbox to enable the Complexity rule.

Select a number from the Must contain at least dropdown. This rule rejects passwords if they don't contain characters from at least the specified number of character sets. This number must be less than or equal to the number of character sets selected below it.

Select the checkbox beside each required character set. Password Policy Enforcer (PPE) has seven character sets. The Policy Properties page has more information about PPE's character sets. You can also use the Characters (Granular) rules to customize the default character sets.

If the number in the dropdown is less than the number of selected character sets, then users have some flexibility in their choice of characters. For example, in the preceding screenshot, the password must contain only three of the four selected character sets.

note

This rule uses custom character set definitions from the Characters (Granular) rules, even if you disable the granular rules.

Select the Passwords must always comply with this rule checkbox to make the Complexity rule mandatory. Rules are mandatory by default, but you can make some of them optional by changing the Passwords must comply with setting on the policy's Properties tab. The Passphrases feature can still disable a mandatory rule.