windows-itpro-docs icon indicating copy to clipboard operation
windows-itpro-docs copied to clipboard

Password Max Length Guidance is No Longer Sufficient

Open DenkertM opened this issue 2 years ago • 1 comments

As of March 2022, this page no longer meets the guidlines of NIST SP 800-62 Paragraph 5.1.1.2.

This guidance states "Verifiers SHALL require subscriber-chosen memorized secrets to be at least 8 characters in length. Verifiers SHOULD permit subscriber-chosen memorized secrets at least 64 characters in length."

It is recommended that the guidance from Microsoft is updated to reflect the NIST guidance.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

DenkertM avatar Mar 04 '22 15:03 DenkertM

Thanks @DenkertM for the feedback. I'm checking with the content owner, as it looks like there's been some previous discussions around this setting. For example, see #6947 (which references several others).

aczechowski avatar Aug 08 '22 15:08 aczechowski

@DenkertM thank you for your contribution. Can you please elaborate how the article is not reflecting the NIST guidelines? I just updated the article with "Set Minimum password length to at least a value of 8". I'm not sure if you were referring to that sentence.

✅ "Verifiers SHALL require subscriber-chosen memorized secrets to be at least 8 characters in length"

Windows also allows passwords longer that 64 characters in length, so it fulfills the second NIST requirement ✅"Verifiers SHOULD permit subscriber-chosen memorized secrets at least 64 characters in length."

The article that you are pointing out, is about Minimum password length.

paolomatarazzo avatar Nov 01 '22 19:11 paolomatarazzo