Choosing a password
When a password is created or changed, it cannot be a commonly used password. This applies when:
- a shopper registers for an account
- a shopper creates an account during checkout
- a shopper changes their password, or resets a forgotten password
- an administrator creates a user, or sets a new password on an existing user
If the password is too common, the form shows: This password is too common and easy to guess. Please choose a different one.
The password is not saved. Choose a different one and submit again.
The check looks for an exact match. Capital letters count, so password and Password are not the same password. Passwords people often try, such as password, 123456, Password1, and Welcome1, are rejected.
Passwords that are already in use
A password that is already on an account keeps working. Signing in does not force a change, even if that password would be rejected if someone tried to choose it today. The check runs only when a new password is chosen.
Other password rules
A store can also have its own password policy. That policy can require a minimum length, a capital letter, a number, a special character, or a password that has not been used recently. Those rules still apply when password policies are turned on for the store.
The common-password check runs even when password policies are turned off.
A new store starts with a minimum length of 12 characters. An administrator can change the store's password policy after that. A store that was already live keeps the password policy it already had.