Problem
If an admin’s password does not meet the minimum password policy, the following error occurs when they log in to the Admin Area:
You cannot use that password. Choose a different password.
Cause
WHMCS automatically re-hashes an admin’s password using a more secure algorithm the first time they log in with it. The stored password must meet the minimum password policy.
Passwords must be at least 12 characters long by default (an administrator may require more, up to a maximum of 64) and contain at least one letter and one number. We also recommend including symbols and both uppercase and lowercase letters.
If the admin’s existing password does not meet this policy, the system cannot complete the hash upgrade and displays this message instead. The admin’s password remains the same. Only the hash upgrade fails.
Solution
To resolve this, set a new password for the admin that meets the minimum password policy:
- The admin can change their own password at Account () > My Account.
- If the admin cannot log in, use the steps in Reset an Admin Password.
After the admin sets a compliant password, the system hashes and stores it under the current policy and the message no longer appears.
Last modified: 2026 September 30