Yandex Cloud
Search
Contact UsTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity Hub
    • Organization
    • Organization membership
    • User groups
    • User pools
    • Password policy
    • Identity federations
    • Domains
    • Applications (SSO)
    • OS Login
    • MFA
    • Controlled organizations
    • My account portal
    • Syncing with Active Directory
    • Quotas and limits
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  • Release notes
  • Yandex Identity Hub Sync Agent release notes

In this article:

  • Password policy settings
  • Password complexity
  • Password lifetime
  • Protection against password guessing
  • Default password policy
  1. Concepts
  2. Password policy

Password policy

Written by
Yandex Cloud
Updated at January 13, 2026
  • Password policy settings
    • Password complexity
    • Password lifetime
    • Protection against password guessing
  • Default password policy

Note

This feature is at the Preview stage.

A password policy brings together rules on creating and updating passwords for pool users.

Password policy settingsPassword policy settings

Users with an administrator or organization owner account have access to password policy settings.

Password complexityPassword complexity

There are two available password complexity options:

  • Any character types: Minimum length depends on the number of character types used in a password. For example, for a password made up of lowercase and uppercase letters, you can set the length of 14 characters, and for a more complex one, 10 characters.

    This is the preferred option as it does not require specific characters and allows users to create strong, yet more memorable passwords.

  • Required character types: Password must contain all specified character types and meet the required length. You can specify the following types of characters:

    • Lowercase letters
    • Uppercase letters
    • Numbers
    • Special characters, e.g., !@#$%^&*

Password lifetimePassword lifetime

Password lifetime is the period of time after which users will have to update their passwords. You can specify a lifetime of up to 730 days or set no limit.

Protection against password guessingProtection against password guessing

To configure protection against password guessing, you can use the following settings:

  • Number of wrong password entries before lockout: 1 to 100.
  • Interval for counting wrong entries in minutes or seconds.
  • Lockout duration in minutes or seconds.

Default password policyDefault password policy

When you create a user pool, it is assigned the following default password policy:

  • Minimum password length for character types used in the password:
    • 4 types: 10
    • 3 types: 11
    • 2 types: 24
  • Minimum password lifetime: Unlimited.
  • Maximum password lifetime: 365 days.
  • Number of wrong password entries before lockout: 15.
  • Interval for counting wrong entries: 10 minutes.
  • Lockout duration: 10 minutes.

Was the article helpful?

Previous
User pools
Next
Identity federations
© 2026 Direct Cursus Technology L.L.C.