Skip to main content

Age (Min) rule

The Minimum Age rule stops users from quickly cycling through a series of passwords to evade the History and Similarity rules. Only domain policies can enforce this rule.

Minimum age rule

Select the Age (Min) checkbox to enable the Minimum Age rule.

Select a number from the days dropdown. Users must wait at least this many days between password changes.

note

The Minimum Age rule is unique because users can't comply with it by choosing a different password; they must wait until the required number of days has elapsed. The Password Policy Client consequently handles rejections by this rule differently from other rules. Instead of displaying the full rejection message, it only displays the Minimum Age rule's reason insert. The Messages page explains how to edit the messages shown to users.

Password Policy Enforcer doesn't enforce this rule during policy testing, but the test log shows the user's password age, and adds a log entry if the Minimum Age rule would have rejected the password change request.