Jump to content

Recommended Posts

Posted

Hi All

 

Just wondering what everyone else's view is on Microsoft's change of advice back in 2019 no longer enforce password expiry? We have our user accounts synced to Microsoft 365 using Azure AD connect and it is not clear if the advice is to no longer enforce expiry just for cloud accounts or on the local network as well or at least I can't find anything definitive. Major downside I can see isthe lack of MFA on the local network. Am quite surprised I cannot find a previous discussion on this topic here on Edugeek...

Posted

I think that guidance from Microsoft will be along the same lines as from the security community more broadly, in that you do away with regular forced password changes to allow users to more easily adopt long passwords. Increasing the minimum password length is the name of the game, and having regular forced changes will undermine that effort by encouraging poor user habits.

 

Personally, I still think having a max password age has some merit for on-prem accounts without any MFA, although that's measured in years rather than weeks or months.

 

This thread might be worth a read through

  • Thanks 1
Posted

Always found password expiry wasn't that great - seemed to encourage people to use weaker passwords that were easier to increment.

 

https://www.ncsc.gov.uk/collection/passwords/updating-your-approach

 

Don't enforce regular password expiry

 

Regular password changing harms rather than improves security. Many systems will force users to change their password at regular intervals, typically every 30, 60 or 90 days. This imposes burdens on the user and there are costs associated with recovering accounts.

 

Forcing password expiry carries no real benefits because:

 

the user is likely to choose new passwords that are only minor variations of the old

stolen passwords are generally exploited immediately

resetting the password gives you no information about whether a compromise has occurred

an attacker with access to the account will probably also receive the request to reset the password

if compromised via insecure storage, the attacker will be able to find the new password in the same place

  • Thanks 1
Posted
Trying to guage what others are doing currently. Are you gentleman still enforcing expiry locally or decided to turn off?
Posted
Trying to guage what others are doing currently. Are you gentleman still enforcing expiry locally or decided to turn off?

 

Not expiring our passwords. Set complexity rules and encourage long passwords. A single, unique, complex password is much better than an easy password with a number that increments, which, lets be honest, is what staff will inevitably do.

Posted
Trying to guage what others are doing currently. Are you gentleman still enforcing expiry locally or decided to turn off?

* and gentlewomen.

 

We don't ask users to change passwords periodically for the reasons linked above.

Posted (edited)

The guidance has very much changed in the last couple of years and we have had to adapt.

 

NCSC do say use 3 different words, min 16 characters and dont expire.

 

We use Specops password auditor to audit our Domain passwords.

 

The thing is it would be great if MS could build in a breach checker instead of paying a fortune for 3rd parties.

 

Just digressing a bit, the new MS licensing model is a bit.. interesting in terms the "light users" who dont fall under the EQU have to be licensed additionally to receive 2FA. Doesn't make sense to me!

Edited by timbo343
  • Thanks 1
Posted

 

The thing is it would be great if MS could build in a breach checker instead of paying a fortune for 3rd parties.

 

 

If you have Azure AD P1 you can make use of Azure Ad Password Prection on prem which blocks both passwords in Microsoft global banned list and let’s you add custom base terms, handy to prevent users using company name or variant in their password and also stops them using their username as their password (they do try). It applies to all accounts so if you have weaker passwords for students based on something weak like dob they will get blocked, can be run in audit mode to identify users using weak passwords, it logs which list (Microsoft or custom) that the password came from.

Posted
In AD we have always had 8 character passwords. To encourage longer passwords what is the easiest way to move from minimum 8 character passwords to minimum 12? Do we have to force users to change passwords in one go? Can we set a password change to a 12 character one at next password change?
Posted
In AD we have always had 8 character passwords. To encourage longer passwords what is the easiest way to move from minimum 8 character passwords to minimum 12? Do we have to force users to change passwords in one go? Can we set a password change to a 12 character one at next password change?

 

Could you set up Fine Grained Passwords so that you could do it group by group and assign minimum password requirements that way. Set a new policy or change an existing policy so that anyone who changes with password will be forced to meet the new requirements.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...