17

Dear Microsoft 365 admins,
It's 2021 - get off your ass and uncheck the box that forces me to change my password just because it's been 90 days. NIST has been advising against this for years, and now (finally!) Microsoft has followed suit. Forced password cycles are annoying and actually FUCKING ENCOURAGE USERS TO USE SHITTY PASSWORDS! Don't believe me? Here - fucking read it for yourselves:

"Don't require mandatory periodic password resets for user accounts."

https://docs.microsoft.com/en-us/...

Comments
  • 6
    Now tell this exact thing to my company's security department 🤣
  • 6
    @iiii Dude, I'm SOOO close to opening a support desk ticket and citing this article. If they close it without "fixing the issue", I can then forward it to their manager citing that their staff is choosing to ignore NIST and Microsoft recommended best practices for password security >:)
  • 1
    Wenn finally got it removed from our security policies last year.
  • 1
    Lets hope that it gets dropped from PCI-DSS
  • 0
    @Linux That and the freaking yearly audits, am I right? I mean, come on - we've proven to live up to your standards and beyond first 700 times, give it a rest already!
Add Comment