security baseline

Latest

  • SOPA Images via Getty Images

    Microsoft knows password-expiration policies are useless

    by 
    Christine Fisher
    Christine Fisher
    04.24.2019

    Microsoft admitted today that password-expiration policies are a pointless security measure. Such requirements are "an ancient and obsolete mitigation of very low value," the company wrote in a blog post on draft security baseline settings for Windows 10 v1903 and Windows Server v1903. Microsoft isn't doing away with its password-expiration policies across the board, but the blog post makes the company's stance clear: expiring passwords does little good.