Password Best Practices and Expiration Policies

Thomas Hunt
Thomas Hunt

Creating Strong Passwords

A secure password is your first defense against unauthorized access. Our policy requires a minimum of 14 characters, including a mix of uppercase letters, lowercase letters, numbers, and symbols. We strongly suggest using passphrases—sequences of random words that are easy for you to remember but difficult for a computer to guess through brute force. For example, 'Correct-Horse-Battery-Staple' is significantly stronger than a short word with complex symbols. Avoid common words found in the dictionary, as modern cracking tools use advanced algorithms to guess these combinations in seconds. The goal is to create high entropy, making the time required to crack the password mathematically unfeasible.

Understanding Expiration

Corporate passwords expire every 90 days to minimize the window of opportunity for an attacker who may have harvested your credentials. You will receive automated email reminders starting 14 days before expiration. Do not ignore these notifications. If your password expires, you will lose access to email, VPN, and all internal portals until you contact IT for a manual reset. This manual reset process requires identity verification and can lead to significant downtime. We recommend changing your password as soon as you receive the first 14-day warning to ensure a smooth transition across all your logged-in devices.

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.