{"id":136327,"date":"2019-04-29T19:06:45","date_gmt":"2019-04-29T19:06:45","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=136327"},"modified":"2025-07-01T22:03:55","modified_gmt":"2025-07-02T05:03:55","slug":"microsoft-password-expiration","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/microsoft-password-expiration\/","title":{"rendered":"PC Security: Microsoft changes its mind on certain password protocols"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-136329\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/06\/Password_header_wdypeh.jpg\" alt=\"a password combination lock\" width=\"700\" height=\"394\" \/><\/p>\n<p>Your password is one of the most important tools you have in your digital security toolbox. Without a strong and secret password, our online accounts, memberships, and subscriptions could end up wide open to cyber-criminals and hackers. As more and more of our lives move online this becomes increasingly more important.<\/p>\n<p><strong>A good password should be long, complex, and not include any recognizable data from your life.<\/strong> For a long time, however, there has been another recognized security requirement that we\u2019ve been forced to adhere to when it comes to our passwords; expiration and renewal. At regular intervals, we\u2019re reminded that our current password will expire soon, and we need to choose a new one.<\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2010\/07\/passwords_header.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">How to: create strong passwords<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/how-to-create-strong-passwords\/\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Read now<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/how-to-create-strong-passwords\/\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p>Without too much thinking, it is easy to see why this might seem like the most secure course of action. If you keep mixing it up, your account will stay secure even if your password falls into the wrong hands. When you add expiration and renewal to password length, complexity, and independence from any past passwords, however, it proves to be a <strong>regular annoyance<\/strong> to everyday users. Having to come up with a unique password that contains a lot of different characters of all types every six months is more difficult than it sounds. It often leads to the wrong password being entered time and again in the first few weeks following the renewal or, even worse, passwords being written down.<\/p>\n<p>The good news is that this regular pain may soon be about to change thanks to a new <a href=\"https:\/\/blogs.technet.microsoft.com\/secguide\/2019\/04\/24\/security-baseline-draft-for-windows-10-v1903-and-windows-server-v1903\/\" target=\"_blank\" rel=\"noopener noreferrer\">security blog post from Microsoft<\/a>. The better news is that Microsoft deciding to remove expiration and renewal from all its password security protocols won&#8217;t compromise your digital security.<\/p>\n<h2>Microsoft now believes password expiration and renewal policies are useless<\/h2>\n<p>According to the Microsoft blog, recent scientific research has been shedding new light onto password policies and, in particular, expiration and renewal. There is little value in constantly forcing users to change their passwords as, \u201cWhen humans are forced to change their passwords, too often they\u2019ll make a small and predictable alteration to their existing passwords, and\/or forget their new passwords.\u201d<\/p>\n<figure id=\"attachment_136331\" aria-describedby=\"caption-attachment-136331\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-136331\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/06\/Microsoft_banned_password_lists_digqmk.jpg\" alt=\"Azure password protection\" width=\"700\" height=\"409\" \/><figcaption id=\"caption-attachment-136331\" class=\"wp-caption-text\">Image via: <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Azure-Active-Directory-Identity\/Azure-AD-Password-Protection-is-now-generally-available\/ba-p\/377487\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> &#8211; Microsoft now believes security protocols like banned password lists are much more secure than expiration and renewal<\/figcaption><\/figure>\n<p>Microsoft goes even further in its dissection of expiration protocols because when you look at the practice in greater detail, it really does begin to fall apart. \u201cIf a password is never stolen, there\u2019s no need to expire it. And if you have evidence that a password has been stolen, you would presumably act immediately rather than wait for expiration to fix the problem.\u201d Simply put, <strong>why change a password if it hasn\u2019t been breached<\/strong>, and if it has, why would you wait until the expiration period is up to change it, and not just do it immediately?<\/p>\n<p>So, Microsoft has laid out its new ideas on password expiration. The blog post goes further, however, and states that the software giant has removed the practice from its security baseline for Windows 10 v1903 and Windows Server v1903. This means, in practice, the change won\u2019t affect too many people, but it gives network administrators the ability to remove password expiration from their office systems. If you have to update your expired passwords in work, you might already be on your last ever password.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">Read more<\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"New scam spotted on the Google Play Store \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/google-play-store-scam-app\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/08\/google-play-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>New scam spotted on the Google Play Store \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"Security alert: new Netflix phishing scams \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/security-alert-new-netflix-phishing-scams\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2019\/02\/netflix-logo-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Security alert: new Netflix phishing scams \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"This ingenious phishing scam is targeting iPhone users \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/iphone-phishing\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/10\/iphone-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>This ingenious phishing scam is targeting iPhone users \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"New year, new scams: what to watch out for in 2019 \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/online-scams-in-2019\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/12\/phishing-scam-hacker-malware-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>New year, new scams: what to watch out for in 2019 \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft now believes password expiration and renewal policies are useless.<\/p>\n","protected":false},"author":9073,"featured_media":136330,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[1072,1126,1663,1027],"usertag":[839],"vertical":[],"content-category":[],"class_list":["post-136327","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-microsoft","tag-online","tag-passwords","tag-security","usertag-vpn"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/136327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=136327"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/136327\/revisions"}],"predecessor-version":[{"id":326197,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/136327\/revisions\/326197"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/136330"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=136327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=136327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=136327"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=136327"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=136327"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=136327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}