I want to
a) enforce custom minimum password complexity requirements
b) enable zero length passwords
Ideally, password complexity requirement would be linked to group membership.
I understand that using external authentication would allow this however the application is for a site which would not otherwise require a directory service and many users would be external to the host organisation. And additionally, internal users WILL be configured for auth in MS AD.