IDF's Password Policy

IDF's Password Policy

The purpose of this Knowledge Base Article is to walk users through the IDF's *Active Directory Password Policy and key steps to setting a strong password that meets the Policy.

IDF's Policy (Up to date as of April 2025)

  1. The last 24 passwords used are remembered. You are strongly encouraged to not reuse old passwords, and recent old passwords cannot be reused.
  2. Maximum Password length is 43 Days. You will be required to change your password at or before the 43rd day. If you do not, you will be forced to change your password before you can continue.
  3. Minimum Password length is 7 characters. Passwords attempted to be used shorter than 7 characters will prompt you to make the password longer.
  4. Meets Complexity Requirements (Must include a special character, number, upper and lowercase letter)
  5. Cannot contain repeating characters (Randomly generated examples of a BAD password with repeating characters: tG27@999, Y8qq!B7)

In order to make a strong password, make sure your password is longer than 7 characters in length, meets complexity requirements and is not similar to something you used in the past. Alternatively you can use a password generator like LastPass to help you generate a strong password or save passwords on a web browser as long as the account used to save the passwords has a strong password. 

NEVER save passwords to a notepad, word document, excel file or any other easy to decipher filetype. If you must save your passwords, ensure its saved behind an account with a strong password, or make sure to use a Password Manager like ZohoVault or LastPass.

*The Active Directory password Policy is for Desktop Logins, VPN login and Microsoft logins. Subject to change and possibly different for external platforms like Zoho, Adobe, etc.) 
      • Related Articles

      • How to add a password in ZohoVault

        The Purpose of this KB is to walk users through the steps of adding passwords to ZohoVault. Log into ZohoVault HERE (if you do not have access or are having trouble logging in, please contact Michael DeSantis directly or submit a ticket to IT for ...
      • Email Safe Practices

        The purpose of this KB is to clearly outline the standard IT Email safe practices that all users should follow to ensure security standards are met. It is important that security standards be upheld to ensure a safe working environment for all. ...
      • How to use the IDF Learning Portal

        The purpose of this guide is to guide users through the steps of logging in and viewing courses in the IDF Learning Portal. If you have not been invited to the IDF Learning Portal, please contact Michael@impactdf.org or Submit a Ticket Navigate to ...
      • How to share a password in ZohoVault

        The purpose of this KB is to walk users through the steps to sharing a password they have saved in ZohoVault. Please make sure to discuss the intent to share a password with your colleagues first before sharing and NEVER share a password with someone ...
      • How to Report Spam/Phishing Emails

        The purpose of this KB is to guide users through the steps to reporting spam/phishing attempts, while sticking to security safe practices. When addressing potentially unsafe emails, its important to first and foremost make sure you are following ...