The current-- non-configurable-- password length in the Change Password dialog (for Windows systems) is 14 characters. This was set, presumably, because that is the maximum length for NT passwords.
Because password hashing attacks are so much faster now, and Windows NT is a minority OS, I believe it would be a good idea to increase the default password length in the Change Password dialog.
Ideally, the length would be configurable. Even better, it would be part of a configurable policy which could be applied to management sets, systems, or even individual accounts, along with defaults for complexity. This would allow legacy systems to have one set of defaults while newer and/or more security systems have another set of defaults.