AD Server 2016 Complexity Requirements Disabled But Still Being Enforced

Joe Hinkle 141 Reputation points

FYI - My domain functional level is still set to 2008 R2 at this time.

We have decided to get away from short complex passwords in place of longer simpler ones. I set my AD to the below settings and they show up correctly in gpresult/h output.html.


When I try to change my password to "my wife is named mary" I cannot change my password. But if I change it to !#1122Wordword it takes the password just fine. I find other people asking about this online but never see an answer. How do I get the complexity requirements to go away?

A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,741 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,370 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,848 questions
0 comments No comments
{count} votes

Accepted answer
  1. Gary Reynolds 9,391 Reputation points

    Hi @

    Try running Get-ADDefaultDomainPasswordPolicy -Current LoggedOnUser powershell command to confirm the password policy has been applied to the domain. Or you can open secpol.msc to view the password policy.


    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Joe Hinkle 141 Reputation points

    Thank you that was the issue. I had to use the set- commmand to change some of the cofigs then I had to reboot my PC for the change to take affect. Running gpupdate/force did not fix it, I had to reboot.

    0 comments No comments