Forum Discussion
Mark Roberts
Aug 16, 2017Copper Contributor
Password Notifications
Hi there, All my users are saying they are not getting notified that there password is going to expire - Example - The baloon in outlook saying your password is going to expire in X number of da...
- Aug 18, 2017
Recently the guy who ones wrote the advice for password creation and regular changing it confessed that he was sorry for what he wrote. He said that he now advices to never force a password change (e.g. every 3 months).
When you go to securescore.office.com you will find a similar advice from Microsoft:
"While this is not the most intuitive recommendation, research has found that when periodic password resets are enforced, passwords become weaker as users tend to pick something weaker and then use a pattern of it for rotation. If a user creates a strong password: long, complex and without any pragmatic words present, it should remain just as strong is 60 days as it is today. It is Microsoft's official security position to not expire passwords periodically without a specific reason."
Michiel van den Broek
Aug 18, 2017Iron Contributor
Recently the guy who ones wrote the advice for password creation and regular changing it confessed that he was sorry for what he wrote. He said that he now advices to never force a password change (e.g. every 3 months).
When you go to securescore.office.com you will find a similar advice from Microsoft:
"While this is not the most intuitive recommendation, research has found that when periodic password resets are enforced, passwords become weaker as users tend to pick something weaker and then use a pattern of it for rotation. If a user creates a strong password: long, complex and without any pragmatic words present, it should remain just as strong is 60 days as it is today. It is Microsoft's official security position to not expire passwords periodically without a specific reason."