I stopped following the 'change passwords every 90 days' rule after reading NIST SP 800-63B
Everyone in my office keeps setting calendar reminders to rotate passwords every 90 days, and our IT guy even emailed a reminder last Tuesday. But that old rule was dropped from the NIST guidelines back in 2017 because it just makes people pick weak variations like Summer2024 then Summer2025. I switched my team to long passphrases with a password manager and we have not had a single help desk ticket for lockouts in 8 weeks. The forced rotation thing is the tip people keep repeating that actually makes you less safe. Curious if anyone else pushed back on their company policy and what actually worked.
Watched my own company force the 90 day thing for years and I was that guy who just kept adding a 1 to the end of my password every time it expired, so I guess I was the poster child for why that rule is useless. When they finally dropped it last year I felt kind of dumb for all the times I thought I was being clever with Winter2023 turned into Winter2024. The IT team switched us to a manager and longer passwords and honestly nobody has complained since. What worked for us was just showing the boss that one article about people picking easy patterns, because he never wanted to hear it from me until he read it himself. Your 8 weeks with no lockouts is a pretty solid number to wave at anyone still dragging their feet on this.