The login timeout is a good idea in itself, but the timeframe it is working to is too short.
As for admin passwords, the rules for complexity should be make clear before you create one - I had to retry four times as each time I was told of a new layer of complexity. In the end I went for a much simpler pattern than I usually would just so I can remember the bloody thing.
As I am getting grief from my colleagues about the timeout I will be adding my moans to Link2ICT's in tray!