Security & Infrastructure

Password Policy Generator

Generate an IT password policy your auditors will accept.

Controls

Generated policy
Acme Ltd — Password Policy
Version 1.0 · Effective 2026-08-02

1. Purpose
This policy defines the minimum requirements for creating, storing and managing authentication credentials at Acme Ltd. It applies to all employees, contractors and third parties with access to company systems.

2. Requirements

1. All user account passwords must be a minimum of 14 characters. Passphrases of four or more unrelated words are encouraged.

2. Multi-factor authentication must be enabled for all accounts that access company systems, and is mandatory for all privileged and administrative accounts.

3. All new and changed passwords must be screened against a recognised breached-credential corpus and rejected if a match is found.

4. Accounts must lock for a minimum of 15 minutes after 10 consecutive failed authentication attempts, and repeated lockouts must raise a security alert.

5. All credentials must be stored in the company-approved password manager. Storing credentials in spreadsheets, documents, browsers or source code is prohibited.

3. Enforcement
These requirements must be enforced technically in the corporate identity provider wherever possible. Non-compliance may result in suspension of access and disciplinary action.

4. Review
This policy is reviewed at least annually by the security owner, and after any material security incident.

IT Password Policy — Ready-to-Adopt Template

A NIST SP 800-63B aligned policy document you can rename, sign and hand to an auditor.

One email, no spam, unsubscribe any time.

About this tool

Select the controls that apply to your organisation — minimum length, MFA, breached-password screening, lockout thresholds and rotation rules — and the generator assembles a complete, numbered policy document you can paste into your ISMS.

What modern password policy guidance says

NIST 800-63B recommends long passphrases, screening against breach corpora, and removing forced periodic rotation and composition rules, which push users toward predictable patterns. Multi-factor authentication matters far more than character complexity.

Making the policy enforceable

Every clause should map to a technical control in your identity provider. A policy that cannot be enforced in Entra ID, Okta or Google Workspace is documentation debt, not security.

How to use Password Policy Generator

  1. 1

    Open Password Policy Generator

    Everything runs on this page — there is nothing to install and no account required to use the free features.

  2. 2

    Add your input

    Paste or enter your values in the panel above. The tool updates as you type, so you can iterate quickly.

  3. 3

    Review the output

    Check the result, copy it with one click, and adjust the options until it matches what your system expects.

  4. 4

    Take it further

    Use the security & infrastructure tips below to make the result production-ready, then unlock the gated extras via the form above.

Best practices

  • Follow NIST SP 800-63B: length beats complexity, and forced periodic rotation for standard accounts does more harm than good.
  • Screen new passwords against a breached-credential corpus rather than enforcing character-class rules.
  • Mandate MFA for every privileged account, and prefer phishing-resistant factors (passkeys, hardware keys) over SMS.
  • Enforce the policy technically in your identity provider — a document nobody can violate beats a document nobody reads.
  • Review the policy annually and after every incident, and record the approval date for auditors.

Why Password Policy Generator matters

Infrastructure and security misconfigurations are among the most common root causes of real incidents, and almost all of them are cheap to fix once visible.

Leaving them unaddressed means failed audits, blocked enterprise deals, and avoidable exposure.

Related free & paid tools

Tool nameTypeKey featuresLink
Have I Been Pwned PasswordsFreeBreached-password screening API (k-anonymity)Visit
1Password BusinessOfferPaidEnforces policy and rotation across a teamVisit
BitwardenOfferFreemiumOpen-source password manager with policy controlsVisit
NIST SP 800-63BFreeThe standard your policy should citeVisit

Links marked Offer may be partner links. They cost you nothing extra and never affect which tools we recommend.

More free Veojson tools

Frequently asked questions

References