Every user account that needs to sign in to the Azure AD authentication system must have a unique user principal name (UPN) attribute value associated with that account. The following table outlines the polices that apply to both on-premises Active Directory-sourced user accounts (synced to the cloud) and to cloud-only user accounts.
Property | UserPrincipalName requirements |
Characters allowed |
|
Characters disallowed |
|
Length constraints |
|
The following table describes the available password policy settings that can be applied to user accounts that are created and managed in Azure AD.
| Property | Standard strength passwords | Strong passwords |
|---|---|---|
Characters allowed |
| |
Characters disallowed |
|
|
Password restrictions |
|
|
Password expiry duration | Default value: 90 days Value is configurable using the Set-MsolPasswordPolicy cmdlet from the Azure Active Directory Module for Windows PowerShell. | |
Password expiry notification | Default value: 14 days (before password expires) Value is configurable using the Set-MsolPasswordPolicy cmdlet. | |
Password Expiry | Default value: false days (indicates that password expiry is enabled) Value can be configured for individual user accounts using the Set-MsolUser cmdlet. See Set a password to never expire for instructions. | |
Password history | Last password cannot be used again. | |
Password history duration | Forever | |
Account Lockout | After 10 unsuccessful logon attempts (wrong password), the user will need to solve a CAPTCHA dialog as part of logon. After a further 10 unsuccessful logon attempts (wrong password) and correct solving of the CAPTCHA dialog, the user will be locked out for a time period. Further incorrect passwords will result in an exponential increase in the lockout time period. | |