## TL;DR
The password must be 8+ characters and contain 3 of 4 character types, and cannot contain the username or full name. The usual failure is the password containing part of the user's name. Pick a passphrase-style password that avoids name parts entirely.

## The error
```text
The password does not meet the length, complexity, or history requirements of the domain.
```

## Steps
1. Check the actual policy: on a DC, open Group Policy Management > Default Domain Policy > Password Policy. Expected: you see minimum length, complexity enabled/disabled, history count.
2. Test the candidate password against the rules: 3 of 4 types (upper, lower, digit, symbol) and minimum length. Expected: it passes on paper. Most failures are obvious once checked.
3. Check for the hidden rule: the password cannot contain the samAccountName or more than two consecutive characters of the display name. Expected: no name parts. "Fall2026!" fails for user "fallon" because of "fall".
4. Check password history: the new password cannot match the last N passwords. Expected: genuinely new. Users cycling one character get rejected here.
5. If the policy itself is the problem (e.g. complexity off but a custom filter DLL rejects), check for third-party password filters on DCs. Expected: filter identified. Some orgs add dictionary filters that reject common words silently.

## When to use
- AD rejects a new password during reset or change
- "Does not meet requirements" with no further detail

## When not to use
- Okta or Entra password policy rejections (different policies)
- Account locked (different error)

## Compatibility
- Windows Server Active Directory; fine-grained password policies may override domain defaults

## Variants
### Passes the rules but still rejected
A fine-grained password policy (PSO) with stricter settings applies to this user. Check which PSO wins.
### "Password too recent" immediately after a reset
Minimum password age is set. An admin can clear the restriction or wait it out.

## Why it happens
AD enforces complexity at the domain controller, and the client error message never says which rule failed. The name-containment rule is the one nobody remembers, so it causes most mystery rejections.

## Edge cases
- Service accounts with "password never expires" still must meet complexity at creation.
- Passphrases ("correct horse battery staple" style) satisfy complexity via length and character variety; recommend them.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_5bhimeXlKZQgTHV5V_74VA
