The following limitations are in effect when configuring passwords:
Local password validation rules are not applied to passwords managed by remote authentication tools such as Active Directory, LDAP or a RADIUS server.
Password validation rules are enforced only when the user sets a plain text string as the password. They are not applied to passwords that are configured as a hashed value. For full enforcement, you can prevent administrators from configuring passwords as hashed values, described in Prohibiting hashed passwords using the CLI.
Password validation rules are enforced only when a password is first added to the system. They are not applied to passwords that already exist.