# As an administrator I can enforce the minimum passphrase complexity in my organization settings

**URL:** <https://community.passbolt.com/t/as-an-administrator-i-can-enforce-the-minimum-passphrase-complexity-in-my-organization-settings/2146>\
**Category:** Done!\
**Created:** [October 24, 2019, 10:09am UTC](https://community.passbolt.com/t/as-an-administrator-i-can-enforce-the-minimum-passphrase-complexity-in-my-organization-settings/2146 "2019-10-24T10:09:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlexG](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AlexG](https://community.passbolt.com/u/AlexG)\
**Post date:** [October 24, 2019, 10:09am UTC](https://community.passbolt.com/t/as-an-administrator-i-can-enforce-the-minimum-passphrase-complexity-in-my-organization-settings/2146/1 "2019-10-24T10:09:44Z")

</div>

**Q1. What is the problem that you are trying to solve?**  
When a user creates its passphrase the only requirement is to use 8 o more length, but they still can use passphrase like ‘12345678’. There is an advertise saying its weak but can be ingonerd by the user.

**Q2 - Who is impacted?**  
Everybody.

**Q3 - Why is it important and/or urgent?**  
The passphrase is the weakiest point of security in the system and as an admin I can´t control how complex/weaky is.

**Q4 - What is your proposed solution? (optional)**  
Allow, by config file for example, a way to enable some complexity rules that will be mandatory when creating the passphrase. Just use the same rules as the complexity advertise to enforce what sysadmin wants.

**Q5. Community support**  
People can vote for this idea to show traction:

_Poll ([view on site](https://community.passbolt.com/t/as-an-administrator-i-can-enforce-the-minimum-passphrase-complexity-in-my-organization-settings/2146/1))_

---

<div class="post-metadata">

**Author:** ![remy](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/remy/32/17_2.png) [@remy](https://community.passbolt.com/u/remy)\
**Post date:** [October 24, 2019, 12:42pm UTC](https://community.passbolt.com/t/as-an-administrator-i-can-enforce-the-minimum-passphrase-complexity-in-my-organization-settings/2146/2 "2019-10-24T12:42:56Z")

</div>

@AlexG thanks for the well written entry!

---

<div class="post-metadata">

**Author:** ![kevingimbel](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/kevingimbel/32/671_2.png) [@kevingimbel](https://community.passbolt.com/u/kevingimbel)\
**Post date:** [May 27, 2020, 12:29pm UTC](https://community.passbolt.com/t/as-an-administrator-i-can-enforce-the-minimum-passphrase-complexity-in-my-organization-settings/2146/3 "2020-05-27T12:29:00Z")

</div>

Has there been any progress or further discussion about this? I think it is a rather nice feature

---

<div class="post-metadata">

**Author:** ![cedric](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/cedric/32/3868_2.png) [@cedric](https://community.passbolt.com/u/cedric)\
**Post date:** [May 18, 2024, 5:00pm UTC](https://community.passbolt.com/t/as-an-administrator-i-can-enforce-the-minimum-passphrase-complexity-in-my-organization-settings/2146/4 "2024-05-18T17:00:02Z")

</div>

Feature released with v4.3.0 Pro and cloud editions.

For more information checkout the documentation page [User Passphrase Policies | Passbolt documentation.](https://www.passbolt.com/docs/admin/authentication/user-passphrase-policies/)
