Rebeltech

  • Home
  • About Us
  • Contact Us
  • FAQ
  • Project Enquiry
  • Our Work
  • Our Services
    • Make A Payment
    • Support Tickets
      • Submit Ticket
      • My Tickets
  • Blog

Password1, Password2, Password3 no more: Microsoft drops password expiration rec

April 29, 2019 By Rebeltech Leave a Comment

For years, Microsoft’s baseline security policy has expired passwords after 60 days.

from Ars Technica by Peter Bright

For many years, Microsoft has published a security baseline configuration: a set of system policies that are a reasonable default for a typical organization. This configuration may be sufficient for some companies, and it represents a good starting point for those corporations that need something stricter. While most of the settings have been unproblematic, one particular decision has long drawn the ire of end-users and helpdesks alike: a 60-day password expiration policy that forces a password change every two months. That reality is no longer: the latest draft for the baseline configuration for Windows 10 version 1903 and Windows Server version 1903 drops this tedious requirement.

The rationale for the previous policy is that it limits the impact a stolen password can have—a stolen password will automatically become invalid after, at most, 60 days. In reality, however, password expiration tends to make systems less safe, not more, because computer users don’t like picking or remembering new passwords. Instead, they’ll do something like pick a simple password and then increment a number on the end of the password, making it easy to “generate” a new password whenever they’re forced to.

Read more.

Filed Under: security Tagged With: passwords

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

phone: 865.801.6112

Privacy Policy | Terms of Use

Copyright © 2025 Rebeltech | Log in