How to Disable or Relax Password Policy in Windows Server (Active Directory Domain)

Important:

Method 1 — Change Password Policy in Default Domain Policy

Open Group Policy Management

On your domain controller:

  • Press Win + R

  • Type: gpmc.msc

  • Press Enter

Edit the Default Domain Policy

Navigate to:

Forest  
 └── Domains  
      └── yourdomain.local  
            └── Default Domain Policy

Right-click Default Domain Policy → Edit

Go to Password Policy

Inside the GPO editor:

Set all password requirements to the minimum

Configure:

Setting
Set to

Enforce password history

0

Maximum password age

0 (password never expires)

Minimum password age

0

Minimum password length

0

Password must meet complexity requirements

Disabled

Store passwords using reversible encryption

Disabled

This effectively removes constraints so Entra ID password changes synchronize freely.

Update policy

Run on the domain controller or client:

Last updated

Was this helpful?