password does not meet complexity requirements" ad policy fix
Resolves Active Directory password rejections against complexity policy. Covers what the policy actually checks, the gotchas (like username parts), and how to craft a compliant password. Use when AD rejects a new password. Not for Okta or Entra-only policies.
TL;DR
The password must be 8+ characters and contain 3 of 4 character types, and cannot contain the username or full name. The usual failure is the password containing part of the user's name. Pick a passphrase-style password that avoids name parts entirely.
The error
The password does not meet the length, complexity, or history requirements of the domain.Steps
- Check the actual policy: on a DC, open Group Policy Management > Default Domain Policy > Password Policy. Expected: you see minimum length, complexity enabled/disabled, history count.
- Test the candidate password against the rules: 3 of 4 types (upper, lower, digit, symbol) and minimum length. Expected: it passes on paper. Most failures are obvious once checked.
- Check for the hidden rule: the password cannot contain the samAccountName or more than two consecutive characters of the display name. Expected: no name parts. "Fall2026!" fails for user "fallon" because of "fall".
- Check password history: the new password cannot match the last N passwords. Expected: genuinely new. Users cycling one character get rejected here.
- If the policy itself is the problem (e.g. complexity off but a custom filter DLL rejects), check for third-party password filters on DCs. Expected: filter identified. Some orgs add dictionary filters that reject common words silently.
When to use
- AD rejects a new password during reset or change
- "Does not meet requirements" with no further detail
When not to use
- Okta or Entra password policy rejections (different policies)
- Account locked (different error)
Compatibility
- Windows Server Active Directory; fine-grained password policies may override domain defaults
Variants
Passes the rules but still rejected
A fine-grained password policy (PSO) with stricter settings applies to this user. Check which PSO wins.
"Password too recent" immediately after a reset
Minimum password age is set. An admin can clear the restriction or wait it out.
Why it happens
AD enforces complexity at the domain controller, and the client error message never says which rule failed. The name-containment rule is the one nobody remembers, so it causes most mystery rejections.
Edge cases
- Service accounts with "password never expires" still must meet complexity at creation.
- Passphrases ("correct horse battery staple" style) satisfy complexity via length and character variety; recommend them.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst5bhimeXlKZQgTHV5V74VA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.