Why Forcing Users to Change Passwords Is Bad for Security

Periodic password expiry (e.g. “change your password every 60–90 days”) is no longer considered good practice. Modern guidance is clear:

Do not require password changes unless there is evidence of compromise.

Authoritative Guidance

🇺🇸 United States: National Institute of Standards and Technology (NIST)

“Verifiers and CSPs SHALL NOT require subscribers to change passwords periodically. However, verifiers SHALL force a change if there is evidence that the authenticator has been compromised.”

Source: NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management, §3.1.1.2, item 6 (final, July 2025).

🇬🇧 United Kingdom: National Cyber Security Centre (NCSC)

“Regular password changing harms rather than improves security.”

“Forcing password expiry carries no real benefits.”

Source: UK NCSC Password Administration for System Owners - Don’t enforce regular password expiry.

🇫🇷 France: Agence nationale de la sécurité des systèmes d’information (ANSSI)

“Si la politique de mots de passe exige des mots de passe robustes et que les systèmes permettent son implémentation, alors il est recommandé de ne pas imposer par défaut de délai d’expiration sur les mots de passe des comptes non sensibles comme les comptes utilisateur.”

Source: ANSSI, Recommandations relatives à l’authentification multifacteur et aux mots de passe, R24, 2021.

ANSSI separately recommends expiration for privileged accounts such as administrator accounts (R25).

Microsoft

“Periodic password expiration is an ancient and obsolete mitigation of very low value, and we don’t believe it’s worthwhile for our baseline to enforce any specific value.”

“When humans are forced to change their passwords, too often they’ll make a small and predictable alteration to their existing passwords, and/or forget their new passwords.”

Source: Aaron Margosis, Security baseline (FINAL) for Windows 10 v1903 and Windows Server v1903, Microsoft Security Baselines blog, 2019. See also: Microsoft 365 password policy recommendations.

Research Evidence