Created on
12-31-2025
05:00 AM
Edited on
01-18-2026
02:15 PM
By
Jean-Philippe_P
| Description | This article describes the minimum password policy enforced when upgrading to v7.6.5. |
| Scope | FortiOS v7.6.5 and later. |
| Solution |
FortiOS v7.6.5 introduces a security enhancement where a global administrator password policy is automatically enabled after upgrade. This forces any administrator accounts that do not meet the new requirements to change passwords to a more complex, 12‑character format at the next login. See this document: Password policy enforcement.
After the upgrade, if a system administrator's password does not meet the following minimum requirements, the administrator is prompted to update the password upon login before access is granted.
If a more restrictive password-policy was in place before the upgrade, the more restrictive password-policy is retained. It is possible to disable the global password-policy manually after the upgrade, although this is not recommended.
Before upgrading, it is advised to update the existing password-policy to meet the minimum requirements that will be enforced after the upgrade, and update administrator credentials accordingly. This allows administrators to follow any existing change management procedures when updating credentials.
GUI method:
CLI method:
Note: As part of this change, the lower bound of the minimum-length password-policy parameter is increased from 8 in previous FortiOS versions to 12 in FortiOS v7.6.5. Starting in this version, if a password-policy is enforced, the minimum password length must be at least 12 characters. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.