Hi @Gilberto Fernandez Garza , thanks for the post.
Password and Account security guidelines is differ base on the organisation security and compliance requirements.
standards like NIST, CIS, ISO are some of the security framework and guidelines for improving overall security and compliance based on org needs..
Generally I would recommend to rename the default administrator account in AD to something to non obvious usernames instead of administrator and the rest will be configured through AD password policy domain level. Set password length to 14 with expiration of 60 days. Again this will change based on org needs and there are multiple other policy setting needs to be considering while setting the password policy for better security.