ISSUE 06 · 6 MIN READ ·

You're still forcing password changes every 90 days

Forcing a password change every 90 days trains people into weaker passwords, not stronger ones — and NIST retired the advice. What to do instead, and how to switch it off.

Every ninety days the message goes round the office: time to change your password again. People sigh, take the one they had, and nudge it one notch — Spring2026! becomes Summer2026!, Password3 becomes Password4. It feels responsible. Regular changes sound like the digital equivalent of changing the locks now and then, and for years the security guidance said exactly that, so nobody questions it.

Here’s the awkward part: the ritual almost certainly makes your accounts less safe, not more. The advice it rests on has been formally withdrawn, and the behaviour it produces is precisely the behaviour attackers count on. This isn’t a fringe opinion — it’s the current position of the standards body that put the ninety-day rule on the map in the first place.

That’s the quiet failure in this one: not a broken setting, but a habit everyone trusts, quietly working against the thing it’s meant to protect.

The myth, stated fairly

The belief is reasonable on its face: a password that changes regularly is a moving target, so even if one leaks, it’s only useful for a few weeks before it’s replaced. In an era when the main worry was someone slowly guessing or cracking a stolen password file, forcing everyone to rotate did limit the damage. It became a checkbox in every audit and a default in every system, and it’s easy to see why — “change it often” is simple to say, simple to enforce, and feels like diligence.

So if your organisation still forces a quarterly change, you’re not being careless. You’re following advice that was, for a long time, genuinely the standard.

Why it’s no longer true

Two things changed: what attackers actually do, and what forced rotation does to human beings.

The threat moved. The common attacks now aren’t patient offline cracking — they’re phishing, where you hand over the current password to a convincing fake page, and “credential stuffing”, where a password leaked from one site is tried automatically on all your others. Against both, a ninety-day cycle is almost useless: a phished or stolen password is used within minutes or hours, long before the next scheduled change comes round. Rotation defends against a threat that has largely moved on.

Meanwhile, forced rotation quietly degrades your passwords. Faced with inventing a strong new secret every quarter, people don’t; they pick something they can predict, and shift it by a digit or a season. Attackers know this pattern intimately — given Summer2026!, guessing the next one is not hard. Frequent forced changes push people towards short, formulaic, reused passwords and towards writing them on a note by the screen, because a genuinely strong password you must replace four times a year is a genuinely strong password nobody can remember.

This is why the guidance changed. The United States’ National Institute of Standards and Technology (NIST) — whose earlier advice popularised routine expiry — now says in its digital-identity guidance that you should not force periodic password changes, and should only require a change when there’s evidence a password has actually been compromised. The old advice was withdrawn; the new advice is to make each password strong and long-lived, and to lean on other defences.

There’s a quick way to see whether this bites you.

  1. Find your policy. If you run Microsoft 365 with accounts managed in the cloud, note that Microsoft already sets these to never expire by default — but many tenants switched expiry back on years ago. Check in the Microsoft 365 admin centre under Settings → Org settings → Security & privacy → Password expiration policy. For on-premises Windows/Active Directory, it’s set by Group Policy under Password Policy → Maximum password age. In Google Workspace, it’s in the Admin console under Security → Authentication → Password management, in the Expiration section.

  2. Read the number. If maximum password age is set to 60, 90 or 180 days, forced rotation is on. If it’s set to 0 or “never”, you’re already following the current advice.

  3. Notice the tell-tale signs even without admin access. If you or your colleagues are periodically prompted to change your password and you find yourselves incrementing a number or a season, that’s the myth at work on you right now.

What to do instead

The better default is calmer than the ritual it replaces, and it’s what the current guidance actually recommends.

Turn off scheduled expiry — set passwords not to expire. Change maximum password age to “never” (or 0), so people keep a strong password instead of churning through weak ones. Do this once you’ve the other pieces below in place.

Ask for length, not complexity theatre. A long passphrase — three or four unrelated words — beats P@ss1! on every measure that matters and is far easier to remember. Encourage a password manager so each account gets a different, long, random password nobody needs to memorise.

Put the real defence on the front door. Two-factor authentication (a code or prompt on top of the password) stops the phishing and credential-stuffing attacks that rotation never could. If you do one thing after switching off expiry, make it turning on two-factor for everyone.

Change on evidence, not on the calendar. Keep the ability to force a reset — and use it the moment a password turns up in a breach or an account looks compromised. That’s rotation aimed where it actually helps, instead of at everyone, all the time.

If this feels like doing less, that’s rather the point: you’re dropping a quarterly chore that was quietly weakening your accounts, and replacing it with a couple of settings that don’t need repeating. Fewer reminders, stronger passwords, and a policy that finally matches how accounts actually get broken into.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

One real, fixable exposure every week. Free.