| Previous | Next |
| ERROR_NO_CALLBACK_ACTIVE | ERROR_PWD_TOO_RECENT |
ERROR_PWD_TOO_SHORT
What ERROR_PWD_TOO_SHORT means
The account provider evaluated the new password and rejected it before completing the change. The effective minimum can come from local policy, domain policy, fine-grained password policy, or an external identity provider.
Where it commonly appears
- Password-change and reset operations
- Account provisioning
- Domain joins and service-account rotation
- Applications that call Windows account-management APIs
Likely causes
- The password contains fewer characters than the effective minimum
- The application validated against stale or local policy instead of domain policy
- Normalization or encoding changed the submitted length
- A fine-grained policy applies specifically to the target account
Troubleshooting checklist
- Identify the authoritative account store and effective policy for that account
- Compare character count after the same normalization used by the API
- Check fine-grained domain policies and identity-provider rules
- Avoid recording the rejected password in logs
Guidance for developers
Do not hard-code a minimum as the only client-side rule. Client validation can improve feedback, but the authoritative server result must be handled. Return a policy-oriented message without disclosing unnecessary security details to unauthenticated callers.
Guidance for administrators
Review the effective policy rather than only the local security policy. For service accounts, update rotation tooling so generated credentials satisfy the current minimum.
Example
A domain user is subject to a 16-character fine-grained policy while the application UI enforces only eight characters. The UI accepts the value, but the domain controller returns this code. Querying or documenting the effective policy fixes the user experience.
Related conditions
ERROR_PWD_TOO_LONG describes an upper-bound or provider limitation; ERROR_PWD_HISTORY_CONFLICT and ERROR_PWD_TOO_RECENT describe reuse and minimum-age rules.
References
Looking for a different code? Search another status or error code.
