Password security guide
Facebook Password Requirements and Account Security
Use a unique generated Facebook password and enable two-factor authentication. Confirm current acceptance rules in the official password-change interface.
What are the current Facebook password requirements?
Meta can change validation and does not publish a complete permanent character-policy table in the account-security overview. The authoritative requirement is the validation shown in Accounts Center when you create or change the password. Do not rely on old third-party claims about exact maximum length or allowed symbols.
Create a long unique value, then adjust only if the official interface rejects a character or length. Never weaken passwords for other accounts to match Facebook.
Recommended Facebook password approach
Generate at least 16 random characters when accepted and store the exact value in a password manager. Do not use a name, page title, birth date, brand or a variation of another social password. A creator or business administrator account deserves extra margin because compromise can affect pages, advertising and connected assets.
Enable two-factor authentication
Facebook Accounts Center offers two-factor authentication options that may include an authentication app, text messages and physical security keys depending on account and device. A FIDO2 security key is phishing-resistant for supported flows. Enroll a backup method before removing the current one.
Review sessions, alerts and connected access
Review where the account is logged in, remove unknown sessions and enable login alerts. Business users should review Page roles, Business Portfolio access, advertising permissions and connected Instagram accounts. A new password does not revoke every delegated permission automatically.
Protect recovery and avoid phishing
Keep the recovery email and phone current and secure the email account with its own unique credential and MFA. Open Facebook through a bookmark or typed address. Do not enter credentials after following an urgent message link, and never share a login code with a caller or chat contact.
What to do after suspected compromise
Use the official hacked-account recovery flow, change the password from a trusted device, sign out unknown sessions and review security settings. Check page roles, ad activity and messages. Replace the same or derived password everywhere else.