--- title: Minimum password age (Windows 10) description: Describes the best practices, location, values, policy management, and security considerations for the Minimum password age security policy setting. ms.assetid: 91915cb2-1b3f-4fb7-afa0-d03df95e8161 ms.prod: W10 ms.mktglfcycl: deploy ms.sitesec: library author: brianlic-msft --- # Minimum password age **Applies to** - Windows 10 Describes the best practices, location, values, policy management, and security considerations for the **Minimum password age** security policy setting. ## Reference The **Minimum password age** policy setting determines the period of time (in days) that a password can be used before the system requires the user to change it. You can set passwords to expire after a number of days between 1 and 999, or you can specify that passwords never expire by setting the number of days to 0. If [Maximum password age](maximum-password-age.md) is between 1 and 999 days, the minimum password age must be less than the maximum password age. If Maximum password age is set to 0, **Minimum password age** can be any value between 0 and 998 days. ### Possible values - User-specified number of days between 0 and 998 - Not defined ### Best practices Set **Minimum password age** to a value of 2 days. Setting the number of days to 0 allows immediate password changes, which is not recommended. If you set a password for a user and you want that user to change the administrator-defined password, you must select the **User must change password at next logon** check box. Otherwise, the user will not be able to change the password until the number of days specified by **Minimum password age**. ### Location **Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Password Policy** ### Default values The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page.
Server type or Group Policy Object (GPO) | Default value |
---|---|
Default domain policy |
1 day |
Default domain controller policy |
Not defined |
Stand-alone server default settings |
0 days |
Domain controller effective default settings |
1 day |
Member server effective default settings |
1 day |
Effective GPO default settings on client computers |
1 day |