View the security misconfiguration catalog
  • Misconfiguration Name
  • Secure password length is not configured (must be set to 15 characters)
  • Description
  • Using more characters in a password requires an attacker to try numerous combinations to crack the password. You can enforce end-users to use 15 characters in their passwords.
  • Severity
  • Critical
  • Category
  • Password Policy
  • Resolution
  • Follow the below steps in GPO to resolve the misconfiguration. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Password Policy -> "Minimum password length" to at least "15" characters.
  • Does remediation require reboot?
  • No