Office 365 Password Policy

This article focuses on Office 365 password policy.

Allowed Characters

Following are the allowed characters in Office 365 user password:

  • a - z
  • A - Z
  • 0 - 9
  • @ # $ % ^ & * – _ + = [ ] { } | \ : ‘ , . ? / ` ~ “ < > ( ) ;

Disallowed Characters

Following are disallowed characters in Office 365 user password:

  • Unicode characters like !, ¥, Ą, Ə, ɖ, o̕, Љ, Ԁ, Ա, ؟, ܀, ހ, ߄ etc
  • spaces

Office 365 User Password

Office 365 password must contain minimum 8 characters and maximum 16 characters and cannot contain a user name. It requires 3 out of 4 the following:

  • Lowercase characters
  • Uppercase characters
  • Numbers (0 - 9)
  • Symbols like @ # $ % ^ & * – _ + = [ ] { } | \ : ‘ , . ? / ` ~ “ < > ( ) ;

Rules

Following are some of the rules applied to Office 365 user password:

  • Password history - Last password cannot be used again
  • Password expiry notification - Default value is 14 days (User is informed before 14 days about the password expiration)
  • Password expiry duration - Default value is 90 days (Password is expired and user needs to set a new password)
  • Password history duration - Forever
  • Account lockout - After 10 unsuccessful attempts of entering wrong password, the user needs to solve the CAPTCHA dialog

Examples

Following are the valid password examples:

  • Summer2015
  • @may2016
  • @Summerset

Following are invalid password examples:

  • Summer
  • summer2015
  • May 2015