Make sure that it also remembers the last six passwords or more so they don't just repeat the same passwords over and over again.
Most common passwords at the lawfirm I worked at were:
password
passme
passment
Those were the passwords they used to reset the passwords for those who forgot their passwords, then they forgot how to change the password. If forced to change their password, they'd forget it and call the help desk anyway the next logon.