--- title: Maximum password age (Windows 10) description: Describes the best practices, location, values, policy management, and security considerations for the Maximum password age security policy setting. ms.assetid: 2d6e70e7-c8b0-44fb-8113-870c6120871d ms.prod: W10 ms.mktglfcycl: deploy ms.sitesec: library author: brianlic-msft --- # Maximum password age **Applies to** - Windows 10 Describes the best practices, location, values, policy management, and security considerations for the **Maximum password age** security policy setting. ## Reference The **Maximum password age** policy setting determines the period of time (in days) that a password can be used before the system requires the user to change it. You can set passwords to expire after a number of days between 1 and 999, or you can specify that passwords never expire by setting the number of days to 0. If **Maximum password age** is between 1 and 999 days, the minimum password age must be less than the maximum password age. If **Maximum password age** is set to 0, [Minimum password age](minimum-password-age.md) can be any value between 0 and 998 days. **Note** Setting **Maximum password age** to -1 is equivalent to 0, which means it never expires. Setting it to any other negative number is equivalent to setting it to **Not Defined**. ### Possible values - User-specified number of days between 0 and 999 - Not defined ### Best practices Set **Maximum password age** to a value between 30 and 90 days, depending on your environment. This way, an attacker has a limited amount of time in which to compromise a user's password and have access to your network resources. ### Location **Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Password Policy** ### Default values The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page.
Server type or Group Policy Object (GPO) | Default value |
---|---|
Default domain policy |
42 days |
Default domain controller policy |
Not defined |
Stand-alone server default settings |
42 days |
Domain controller effective default settings |
42 days |
Member server effective default settings |
42 days |
Effective GPO default settings on client computers |
42 days |