Minimum password age (Windows)

Module: Password Strength

Supported Platforms: Windows 2000, Windows 2003, Windows 2008, Windows Vista, Windows XP

This check verifies that the Windows password settings include a minimum age and that a password cannot be changed before the specified number of days has elapsed since the previous password change. The valid range of minimum password age is 0 to 998 days.

The following table lists the error message for the check.

Table: Error message for Minimum password age

Message String ID and Category

Platform and Message Numeric ID

Message Title and Description

Additional Information

String ID: ESM_MIN_PASSWD_AGE_TOO_LOW

Category: Policy Compliance

  • Windows 2000 (105332)

  • Windows 2003 (205332)

  • Windows 2008 (248332)

  • Windows Vista (228332)

  • Windows XP (200332)

Title: Minimum password age too low

Description:The minimum password age is set too low. Users have trouble remembering passwords that change too often. Users may cause security breaches by writing down passwords instead of memorizing them. The recommended minimum password age is 14 days.

Severity: yellow-1

Correctable: false

Snapshot Updatable: false

Template Updatable: false

Information Field Format: [Min age: %s; expected: %s]