You are correct.
Target account passwords are governed by a password composition policy.
The password requirements under Global Settings are only used by local* PAM users when setting/changing the password they use to log into PAM.
* password requirements are not enforced for users who authenticate via LDAP, Radius, or SAML; those systems manage their own passwords.