Simple password policy
This module enforces a simple password policy with configurable rules for length, character types, and preventing reuse of old passwords. It also allows for password expiration notifications and can be bypassed under certain conditions.
INTRODUCTION
This module implements a simple account policy with the following configurable set of fixed rules:
- minimum password length
- minimum amount of lowercase chars (a-z)
- minimum amount of uppercase chars (A-Z)
- minimum amount of numeric chars (0-9)
- minimum amount of special chars not(a-z A-Z 0-9)
- minimum amount of old password allowed
- period in which old passwords are not allowed
- check paswword is not similar to username
The module will also notify the user his password is expired and will send a warning mail ahead of time.
- expire the password after period
- send email password is about to expire
Password policy can be ignored using:
- ignore password policy expiration check on configured routes:
- don't apply policy for users matching a pattern
- applying the permission 'bypass password policy'
SIMILAR MODULES
If you want more control over the rules and how a password policy should apply, the password_policy module is more
enhanced. If you want more strict rules, password_strength might be an option too. This module was build to keep it
simple.
* password_policy
* password_strength
REQUIREMENTS
This does not require any other module.
RECOMMENDED MODULES
None
INSTALLATION
Install as you would normally install a contributed Drupal module. Visit
https://www.drupal.org/node/1897420 for further information.
CONFIGURATION
General usage
After installing the module is configured with these default rules:
- min_length: 12
- min_lowercase: 1
- min_uppercase: 1
- min_numeric: 1
- min_special: 1
- min_old: ''
- min_old_age: ''
- similar_username: ''
- ignore_routes:
- 'entity.user.edit_form'
- 'system.ajax'
- 'user.logout'
- 'admin_toolbar_tools.flush'
- 'user.pass'
- 'image.style_public'
- ignore_users: { }
- expire_period: '1 year'
- expire_warning: '3 weeks'
Configuration is found under the "People" configuration item.
/admin/config/people/password_policy
Depends on
Dependencies of the latest stable release
- user Drupal core
Required by
Tracked projects that depend on this one
No tracked projects depend on this one yet.
Activity
Release Timeline
Releases
| Version | Type | Core | Release date | |
|---|---|---|---|---|
| 1.1.4 | Stable | 10–11 | Aug 25, 2026 | |
| 1.1.3 | Stable | 10–11 | Aug 21, 2026 | |
| 1.1.2 | Stable | 10–11 | Aug 14, 2026 | |
| 1.1.1 | Stable | 10–11 | Aug 14, 2026 | |
| 1.1.0 | Stable | 10–11 | Aug 13, 2026 | |
| 1.1.x-dev | Dev | 10–11 | Aug 13, 2026 | |
| 1.0.5 | Stable | 10–11 | Oct 15, 2024 | |
| 1.0.4 | Stable | 8–10 | Sep 15, 2023 | |
| 1.0.3 | Stable | May 31, 2023 | ||
| 1.0.2 | Stable | Feb 14, 2023 | ||
| 1.0.1 | Stable | Feb 14, 2023 | ||
| 1.0.x-dev | Dev | Feb 14, 2023 | ||
| 1.0.0 | Stable | Jan 30, 2023 |