How difficult is it to configure this? Users should definitely choose passphrases of sufficient length and sufficient types to be secure. This is unfortunately an infamously tricky area of security to get right - and the password ought not be reused or used for the Apple Id login or anywhere else.
log(10000)/log(2) ~ 15.