Hey @Andres Felipe Mejia Sanchez
Unfortunately the documented password policy limits are to remember the last password only.
There is a uservoice suggestion for this item here.
For your options to implement other controls, you could do the following. Make sure to discuss with your PCI compliance experts first ;)
- Implement Sync from an on-premise directory - Apply your policies within Active Directory
- Federate with an identity provider which enables password controls - Apply policies within the external IDP
- Go Password-less
Personally, I would suggest going password-less - I use a yubikey & windows hello for all my sign-ins and the experience is great.