# Password Policy

**URL:** <https://forum.keycloak.org/t/password-policy/7676>\
**Category:** Securing applications\
**Tags:** authentication\
**Created:** [March 2, 2021, 8:58am UTC](https://forum.keycloak.org/t/password-policy/7676 "2021-03-02T08:58:27Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![npasic](https://avatars.discourse-cdn.com/v4/letter/n/e19b73/32.png) [@npasic](https://forum.keycloak.org/u/npasic)\
**Post date:** [March 2, 2021, 8:58am UTC](https://forum.keycloak.org/t/password-policy/7676/1 "2021-03-02T08:58:27Z")

</div>

I’ve been using Keycloak as Auth system. I’ve configured password policies in the Keycloak Admin Console, those policies are applicable when I try to update the password in the user Account however when I’m creating a user thru Java code, those policies are ignored.  
Do you have an idea how am I suppose to get those policies and test if a password is valid on those policies?
