Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity Hub
    • Organization
    • Organization membership
    • User groups
    • User pools
    • Password policy
    • Authentication policies
    • Identity federations
    • Domains
    • OS Login
    • MFA
    • Controlled organizations
    • Branding
    • My account portal
    • Audit logs and login logs
    • Sessions
    • Syncing with Active Directory
    • Quotas and limits
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  • Release notes
  • Yandex Identity Hub Sync Agent release notes

In this article:

  • Password policy settings
  • Password complexity
  • Password uniqueness
  • Password lifetime
  • Protection against password guessing
  • Default password policy
  1. Concepts
  2. Password policy

Password policy

Written by
Yandex Cloud
Updated at May 19, 2026
View in Markdown
  • Password policy settings
    • Password complexity
    • Password uniqueness
    • Password lifetime
    • Protection against password guessing
  • Default password policy

A password policy brings together rules on creating and updating passwords for pool users.

Password policy settingsPassword policy settings

Note

A password policy only applies to passwords set by users. It does not apply to automatically generated passwords.

Users with an administrator or organization owner account have access to password policy settings.

Password complexityPassword complexity

There are two available password complexity options:

  • Any character types: Minimum length depends on the number of character types used in a password. For example, for a password made up of lowercase and uppercase letters, you can set the length of 14 characters, and for a more complex one, 10 characters.

    This is the preferred option because it does not require particular characters and allows users to create passwords that are stronger yet easier to remember.

  • Required character types: Password must contain all specified character types and meet the required length. You can specify the following types of characters:

    • Lowercase letters
    • Uppercase letters
    • Numbers
    • Special characters, e.g., !@#$%^&*

Password uniquenessPassword uniqueness

The password can be checked against the database of common passwords. If a user tries to set such a password, the system will reject it: these are easily guessed by attackers.

Password lifetimePassword lifetime

Password lifetime is the period of time after which users will have to update their passwords. You can specify a lifetime of up to 730 days or set no limit.

Protection against password guessingProtection against password guessing

To configure protection against password guessing, you can use the following settings:

  • Number of wrong password entries before lockout: 1 to 100.
  • Interval for counting wrong entries in minutes or seconds.
  • Lockout duration in minutes or seconds.

Default password policyDefault password policy

When you create a user pool, it is assigned the following default password policy:

  • Minimum password length for character types used in the password:
    • 4 types: 10
    • 3 types: 11
    • 2 types: 24
  • Minimum password lifetime: Unlimited.
  • Maximum password lifetime: 365 days.
  • Password check against the database of common passwords is on.
  • Number of wrong password entries before lockout: 15.
  • Interval for counting wrong entries: 10 minutes.
  • Lockout duration: 10 minutes.

Was the article helpful?

Previous
User pools
Next
Authentication policies
© 2026 Direct Cursus Technology L.L.C.