Hi, We've been experimenting with this feature, and there appears to be no way of enforcing a password history policy.
Something along the lines of "The user cannot use a password that was one of their last 6 passwords."
As it stands, if we were to set a password expiry policy, a user could literally just re-enter their existing password and carry on.
You'd think that would be the most fundamental policy to implement; has anyone else come across anything like this at all - maybe I'm just missing it?
Thanks