Settings -> Password Policy controls what a generated app-account password looks like. Save Policy writes it as the fleet default; Test Generate tries the form's current values without saving, so a broken combination gets caught before it breaks the real Generate button for someone else.
See password-policy.md for the full technical story.