If you configured ZCS to use the Zimbra directory server for internal authentication, you can set password usage options. If you use external authentication, password options configured in COS or accounts are ignored.
You set up an account's initial password when creating the account. After that, users can change their passwords, if Password Locked is not enabled. Passwords are stored in encrypted fashion in the directory server and they cannot be retrieved. If users forget their password, you must create a new password.
The password restrictions can be configured in the COS and in the Account. The attributes that can be set include:
Password length. Set the minimum and maximum length for the password. The default minimum is 6 and the maximum is 64.
Password aging. Set the minimum and maximum age in days that a password can be used before it can be reset. Users can change their passwords at any time between the minimum and maximum age. They must change it when the maximum password age is reached.
Minimum upper case characters. Upper case A - Z.
Minimum lower case characters. Lower case a - z.
Minimum punctuation symbols. Non-alphanumeric, for example !, $, &, %, etc.
Enforce password history. This is the number of unique new passwords that a user must create before he can reuse an old password. Password history is used to ensure that new passwords were not used in the recent past.
Password locked. If this box is checked, users cannot change their password. This option should be set if External LDAP or External Active Directory is configured for authentication
Must change password. This option is on the account General tab only. If this box is checked, users must change their passwords the first time they log on after the password is set by the administrator. This feature is applicable only if the Zimbra directory server is used for authentication.
Enable failed log in lockout. When this is checked, you can set rules for how to handle an account if a password is invalid.