Cyber Cloud Ops Logo
Microsoft Intune

Control Device Password History via Intune: Quick and Effective Guide

By Admin User
May 16, 2025
7 min
Control Device Password History via Intune: Quick and Effective Guide

In this article, I’ll walk you through how to enable the Device Password History policy using Microsoft Intune — a key step toward strengthening your organization's password hygiene.

The Device Password History setting helps prevent users from reusing their previous passwords on managed devices. When enabled, IT administrators can define how many past passwords the system remembers, ensuring users create unique credentials each time they update their password. This significantly reduces the risk of credential reuse and improves overall security.

In Microsoft Intune, this setting is part of the Device Restrictions configuration profile and can be applied across multiple platforms — including Windows, macOS, iOS/iPadOS, and Android. By specifying a password history count (e.g., remembering the last 5 or 10 passwords), organizations can enforce security standards and align with regulatory compliance requirements.

Once deployed via Intune, the policy automatically applies to all targeted devices. Any attempt to reuse an old password will be blocked, reinforcing secure practices across the environment. Combined with other password complexity and expiration rules, this policy plays a vital role in a modern endpoint protection strategy.

📑 Table of Contents

  1. What is the Device Password History Policy? Understand the purpose and security benefits of enforcing password history on managed devices.

  2. How to Create a Configuration Profile in Intune Step-by-step instructions to enable and configure the Device Password History Policy using Microsoft Intune.

  3. Monitoring Policy Deployment in Intune Learn how to track and verify successful deployment across your devices.

  4. End User Experience Discover what users will see and how the policy affects their password update process.

Here’s a concise table explaining key points about the Device Password History Policy Configuration in Microsoft Intune.

Control Device Password History via Intune - Table - 01

✅ Create a Configuration to Enable Device Password History Policy in Intune

To enable the Device Password History Policy using Microsoft Intune, follow the steps below:

Sign in to the Microsoft Intune Admin Center using your administrator credentials.

In the left-hand menu, go to:

  1. Devices

  2. Windows

  3. Configuration

  4. New Policy

Control Device Password History via Intune - Fig. - 01

Next, we will create a new configuration profile from scratch. First, we need to provide the options mentioned below.

  1. Under Platform, select: Windows 10 and later

  2. Under Profile type, choose: Settings catalog

  3. Click Create to start configuring the policy. (See example in Fig. 2 – How to Easily Enable or Disable Device Password History Policy using Microsoft Intune)

Control Device Password History via Intune - Fig. - 02

On the Basics page, enter a name for the configuration profile — for example: “Enable Device Password History Policy.”

In the Description field, you can add: “Enforces password history to prevent users from reusing previous passwords on managed Windows devices.”

Once completed, click Next to proceed.

Control Device Password History via Intune - Fig. - 03

Now it’s time to add the required settings to the configuration profile. In the Configuration settings pane, click + Add settings located at the bottom left of the page.

Control Device Password History via Intune - Fig. - 04
  1. In the Settings picker window, use the search bar to look for: “Device Password History”

  2. This will help you quickly locate the relevant setting.

  3. Next, expand the Device Lock category and select the setting: “Device Password History”

  4. Once selected, click X to close the Settings picker and return to the configuration screen.

Control Device Password History via Intune - Fig. - 05

On the Configuration settings page, locate the Device Password History setting.

Enable the setting and set the value to 5 — this defines how many previous passwords will be remembered and cannot be reused by the user.

Once configured, click Next to continue. 

Control Device Password History via Intune - Fig. - 06

On the Scope tags page, you can leave the setting as Default if no custom tags are required. If your organization uses custom scope tags to segment administrative access, select the appropriate tags based on your policy requirements.

Click Next to proceed.

Control Device Password History via Intune - Fig. - 07

On the Assignments page, assign the configuration profile to the appropriate device group.

Click on Add Groups under the Included Groups section, then select your desired group. In this example, I used “GRP - MS365Education - Test Computers” as the target group.

No filters were applied, and the Excluded Groups section was left blank.

Click Next to continue.

Control Device Password History via Intune - Fig. - 08

On the Review + create page, carefully review all the settings configured for the Enable Device Password History Policy.

If everything is correct, click Create to deploy the policy to the assigned devices.

Control Device Password History via Intune - Fig. - 09

Monitor the Deployment of the Device Password History Policy 

After deploying the policy to the GRP - MS365Education - Test Computers device group, it will be applied as soon as the assigned devices complete a sync with Microsoft Intune.

To monitor the deployment status, follow these steps:

  1. In the Intune portal, navigate to: Devices > Windows > Configuration profiles

  2. Search for the profile named: “Enable Device Password History Policy”

Click on the profile to open it, then check the Device and user check-in status section to view the deployment results and compliance status.

Control Device Password History via Intune - Fig. - 10

🖥️ End User Experience & Client-Side Verification

Once the Enable Device Password History Policy is deployed, it is enforced after the next successful sync between the device and Microsoft Intune. While the end user may not receive a visible notification, the policy ensures that users cannot reuse previously used passwords based on the configured history count.

Client-Side Verification

The MDM Policy Manager applies the Device Password History policy under the Device Lock category. Key parameters such as Enrollment ID, Int Value, Enrollment Type, and Scope may vary depending on the device’s configuration and the method of policy assignment.

Example Parameters (May Vary by Device):

  • Enrollment ID: A unique identifier for the device's MDM enrollment (e.g., B1E9301C-8666-412A-BA2F-3BF8A55BFA62).

  • Int Value: Reflects the applied policy’s setting (e.g., 0x5 to indicate password history count set to 5).

  • Enrollment Type: Indicates how the device is enrolled (e.g., 0x6 for MDM-managed).

  • Scope: Defines whether the policy is applied at user or device level (e.g., 0x0 for device-level).

How to Verify on the Client:

  1. Open Event Viewer on the targeted Windows device.

  2. Navigate to: Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin

  3. Look for Event ID 814 or other related entries indicating successful policy application.

  4. Review the event details and confirm the policy "DevicePasswordHistory" is listed with the correct value and status.

⚠️ Troubleshooting Tips:

  • If the expected value is not applied, confirm that the device has recently synced with Intune.

  • Recheck assignments in the Intune Admin Center to ensure the device is part of the target group.

  • Validate that there are no conflicting policies or settings from other profiles.

  • Refer to Microsoft documentation for advanced troubleshooting based on log output.

📚 More Information

To deepen your understanding of configuring and managing the Device Password History policy in Microsoft Intune, refer to the following official Microsoft resources:

These resources provide detailed guidance for configuring, deploying, and verifying password-related security policies across managed devices using Microsoft Intune.

Thank you!

🖥️ Ricardo Barbosa

📘 MCT Microsoft Certified Trainer | ☁️ Cloud Architect

🌐 Technology Director - https://altelix.com

Originally published on LinkedIn · May 16, 2025 · read the original article
Tags:
MicrosoftIntune
EndpointManagement
Windows11
DeviceManagement
ModernWorkplace
MEM
ITPro
ZeroTrust
MVPBuzz
Keep reading

The full Hardening Windows Endpoints series

One control at a time, with the exact policy paths, the detection and remediation scripts, and the reporting to prove it worked across the fleet.

Browse all articles
Need a hand

Rolling this out across a real fleet?

Reading the guide is the easy part. Designing it for thousands of devices, piloting it without breaking production and proving compliance afterwards is the hard part. That is what we do at ISolutions CloudX.

Talk to ISolutions CloudX

Written by Ricardo Barbosa, Microsoft MVP and MCT. New guide every Wednesday and Friday. Follow on LinkedIn to get the next one.

Posts Sugeridos

Control Device Password History via Intune: Quick and Effective Guide | CyberCloudOps Blog