Minimum password age

Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy


Determines the period of time (in days) that a password must be used before the user can change it. You can set values between 1 and 999 days, or you can allow changes immediately by setting the number of days to 0.

By default, this setting is defined in the Default Domain GPO and in the local security policy of workstations and servers with a value of 0, which allows passwords to be changed immediately.

Note Image Note

The minimum password age must be less than the Maximum password age.

Configure the minimum password age to be more than 0 if you would like to have entered a value for Enforce password history to be effective. Without a minimum password age, the user can repeatedly cycle through passwords until they get to an old favorite. The reason the default settings do not adhere to this recommendation is to support the scenario where an administrator specifies a password for the user and requires that user to change the administrator-defined password when the user logs on. If password history were set to 0, then the user would not have to pick a new password. Thus, password history is set to 1 by default to handle this specific case.