Platform capabilities
Manage Microsoft cloud services, Windows devices, security, documentation, backup, and support from one self-hosted platform.
The Password Policy page in MSPControl is used to define the password requirements and password lifecycle behavior applied to the selected organization. This page allows administrators to configure password length rules, complexity requirements, expiration timing, password history, renewal behavior, notification settings, and optional lockout-related controls.

Because password policy directly affects account security and user sign-in behavior, this page should be treated as a high-impact configuration area. Changes made here can influence how strong passwords must be, how often they need to be changed, whether users are warned before expiration, and whether automatic renewal or additional restrictions are enforced.
The Password Policy page is a centralized place for controlling password rules for the organization. The settings shown on this page define both technical password requirements and operational behavior around password expiration and renewal.
From the screenshots provided, the page includes numeric policy fields, multiple checkboxes, and a final save action. This indicates that MSPControl allows administrators to combine basic password-strength requirements with password-lifecycle rules in one policy screen.
This page is especially useful for organizations that need to align password behavior with internal security standards, compliance expectations, or customer-specific operational requirements.
The expiration and renewal fields determine how long passwords remain valid and how MSPControl should behave before or after expiration. These settings are important because they influence both security posture and user experience.
Max Password Age (days) controls the primary expiration window. A shorter value increases password-rotation frequency, while a longer value reduces the number of forced changes. Min Password Age (days) helps prevent users from changing passwords repeatedly in a short period, which can otherwise make password-history rules less effective.
Notification Days – Before Expiration and Notification Days – After Expiration affect how much warning or follow-up users receive. Auto Renew Days supports workflows where password renewal may be managed automatically under defined conditions.
When Enable Password Complexity is turned on, MSPControl enforces composition rules that require certain character types to appear in the password. In the example shown, the policy requires at least one uppercase letter, one number, and one non-alphanumeric symbol.
Complexity settings are useful when the organization wants to reduce the risk of weak or predictable passwords. These requirements work together with the length settings to form the overall password-strength baseline.
Administrators should make sure the complexity requirements remain realistic for end users while still meeting the organization’s security standard. Overly weak settings reduce protection, while overly restrictive settings can lead to poor password habits if users struggle to remember compliant passwords.
The password policy should be understood as a combined rule set rather than a collection of isolated fields. For example, a strong minimum length combined with complexity requirements and password history creates a much stronger baseline than any one of those settings alone.
At the same time, lifecycle settings such as expiration age, notifications, and renewal timing determine how users interact with those password requirements over time. This means administrators should review the full policy as a complete security workflow instead of adjusting one field without considering the others.
Before saving, administrators should review all numeric values and enabled checkboxes carefully, because even a small policy change can affect many users at once.
Self-hosted. Free license available. No credit card required.