---
title: "Password Security Policy"
description: "Administrators set password strength, complexity requirements and expiration for their organisation from Administration, Security, Security policies."
category: administration-security
section: authentication-and-sso
tags: [admin]
type: Tutorial
lastUpdated: 2026-09-23
locale: en
canonical: https://support.talkspirit.com/en/administration-security/password-security-policy
---

# Password Security Policy


## Password Security Policy

Administrators define the password rules that apply to every member of their organisation. From **Administration** → **Security** → **Security policies** you set three controls: the **Complexity requirements** toggle, the minimum **Password strength**, and the **Password expiration** period. Each control saves as soon as you change it, and the change applies to passwords from the next time each member sets one.

## How do I set the minimum password strength?

Go to **Administration** → **Security** → **Security policies** and choose a value from the **Password strength** menu. The setting is the minimum strength a new password must reach. Talkspirit scores each password by how hard it is to guess, not by counting characters or character types, so a long, uncommon password can pass a level that a short one padded with symbols fails. The five levels, from least to most demanding:

- **No minimum**: any password is accepted. Only the complexity requirements apply, if you have turned them on.
- **Low**: rejects the most common passwords and obvious patterns, such as `123456` or `password`.
- **Medium**: rejects what a scripted attack would find quickly, typically a dictionary word with a couple of digits added.
- **High**: resists a slow offline attack on a stolen password database. Long, uncommon combinations of words reach this level.
- **Very high**: withstands a sustained offline attack. In practice this means a passphrase of several unrelated words.

If your corporate policy is written as a required resistance rather than a character count, pick the level whose description matches it: **High** or **Very high** for policies that demand resistance to offline attacks. The new level is saved as soon as you pick it.

![The Password policy panel on Administration → Security → Security policies for Alpine Tech: the Complexity requirements toggle off, the Password strength menu set to Low, the Password expiration menu set to Never, and the Force a password reset row with its Force reset button](/images/administration-security/password-security-policy/password-policy-panel.png)

> **Note:** Changing the strength does not affect existing passwords. Members keep their current password and only have to choose a compliant one the next time they set a new password.

## How do I enforce complexity requirements?

Turn on the **Complexity requirements** toggle, the first row of the panel. When it is on, every new password must be at least 8 characters long and contain an uppercase letter, a lowercase letter and a special character. Digits only count towards the length, not as one of the required character types. The toggle saves as soon as you switch it.

The strength level and the complexity requirements are cumulative: a new password must clear both. Lowering one never relaxes the other. Whatever the policy, a password is always between 6 and 72 characters long, and the **Change password** dialog in **My Account** asks for at least 10.

## How do I set password expiration?

Choose a value from the **Password expiration** menu to control how often members must change their password:

- **Never**
- **3 months**
- **6 months**
- **1 year**

When the expiration period passes, the member is signed out and must set a new password before they can sign in again. The new password cannot be the same as their current password. Because choosing a period forces members whose password is older than it to renew at their next sign-in, Talkspirit asks you to confirm with **Force renewal** before it saves.

The panel's last row, **Force a password reset**, is a separate one-off action: **Force reset** makes every active member choose a new password the next time they sign in, and it cannot be undone.

## What's Next?

- [Changing my email address](/en/getting-started/changing-your-email-address)
- [Configuring Google Authentication](/en/administration-security/how-to-configure-google-authentication)
- [Signing in to Talkspirit](/en/getting-started/signing-in-to-talkspirit)
- [User Roles and Permissions](/en/administration-security/user-roles)
