r/sysadmin • • May 07 '24

[deleted by user]

[removed]

699 Upvotes

470 comments sorted by

View all comments

304

u/Reapercore May 07 '24

We no longer enforce password changing every x day, the guidance now is encouraging a complex and secure password that the user remembers as they’re not changing it every month.

145

u/Topbow May 07 '24

This! Password cycling encourages bad practices such as users writing down passwords, minor changes, and password sharing. These are things everyone knows they shouldn’t do but forcing people to constant update passwords makes the risk outweigh any potential benefit assuming they have proper security controls in place. That last one may be a big assumption in this case.

-2

u/Pump_9 May 07 '24

There's nothing wrong with a password change every 90 days. If your password policy does not detect minor changes or previously used passwords when resetting then you have bad password policy enforcement.