Microsoft realizes password expiration is poor security

Using Windows 10 at work usually means changing your password every 60 days. Not anymore.
 By  Matthew Humphries  for PCMag  on 
Microsoft realizes password expiration is poor security
Credit: Drew Angerer/Getty Images

PCMag.com is a leading authority on technology, delivering Labs-based, independent reviews of the latest products and services. Our expert industry analysis and practical solutions help you make better buying decisions and get more from technology.

Thinking of a secure password is hard, so demanding a user change it every 60 days fills many with dread and leads to weaker security. Microsoft has realized this and decided to remove default password expiry as a security baseline feature in Windows 10.

When organizations deploy Windows 10 to tens, hundreds, or even thousands of employees, default security out the box is very important. That's why Microsoft provides Windows security baselines, which consist of a group of Microsoft-recommended configuration settings that can be relied upon to provide a more secure operating system.

As part of the baseline, Microsoft in the past stipulated a 60-day password expiration policy, which meant every user was forced to change their password every couple of months (unless an organization changed the configuration). As Ars Technica reports, with the release of Windows 10 v1903, password expiration is being dropped from the baseline because it's actually detrimental to security.

Microsoft explains in its latest draft security baseline for Windows that, "When humans are forced to change their passwords, too often they'll make a small and predictable alteration to their existing passwords, and/or forget their new passwords ... Periodic password expiration is a defense only against the probability that a password (or hash) will be stolen during its validity interval and will be used by an unauthorized entity. If a password is never stolen, there's no need to expire it."

Microsoft also points out that if a password is stolen, the thief has up to 60 days to use it based on this expiration policy, which is ample time to gain entry to a system and cause chaos. So on every level, password expiration simply doesn't work, which is why it's disappearing.

Passwords still need to meet a minimum length requirement, be complex enough so as not to be easily guessed, not have been used before, and stored securely. It may still be the case that individual organizations enforce their own expiration policy, but it seems likely the demand for a new password every few months will impact far fewer workers going forward, and that's a good thing for both their sanity and security.

Topics Microsoft

Mashable Potato

Recommended For You
Google researchers just put a new expiration date on Bitcoin
Bitcoin coin

Microsoft 365 Outlook down: Microsoft breaks silence on outage
Microsoft logo


Instagram denies data breach: So what's up with those sketchy change password emails?
instagram logo against a black background

How to tell if an Instagram password reset email is real
close-up view of Instagram app in the App Store

More in Tech
The Earth is glowing in new Artemis II pictures of home
One half of the Earth is seen floating in space through the open door of the Orion spacecraft.

Doomsday Clock now closest to midnight ever
A photograph of the Doomsday Clock, stating "It is 85 seconds to midnight."

Hurricane Erin: See spaghetti models and track the storm’s path online
A map showing the predicted path of Tropical Storm Erin.

Tropical Storm Erin: Spaghetti models track the storm’s path
A prediction cone for Tropical Storm Erin.

NASA to build a nuclear reactor on the moon by 2030, report states
The lunar surface.

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone


What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.

NYT Connections hints today: Clues, answers for April 2, 2026
Connections game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!