Settings -> Password Policy controls what a generated app-account password actually looks like -- length, letters, numbers, special characters, and word-based passwords, grouped into five cards matching how the standalone MinionWare Password Generator reasons about a password.
Save Policy vs. Test Generate
Save Policy writes the form back as the fleet's saved policy -- this is what the Set Password dialog's own Generate button reads from. Test Generate generates against whatever's currently in the form without saving it -- some combinations that look fine field-by-field are actually invalid (e.g. a single-word password with numbers/symbols centered has no meaningful "center"), so Test Generate lets you catch a broken policy before it's saved and breaks the real Generate button for someone else.
Generating a password
The Set Password dialog's Generate button fills in a compliant password (and the confirm field) from the fleet's saved policy. Every password field has a Show/Hide toggle next to it so you can check what was actually typed or generated.
See also: Disabling a User Account.