realn2s,

Moving on to in general

Microsoft offers the following Password Guidance
https://www.microsoft.com/en-us/research/publication/password-guidance/

Side note, the PDF contains no (visible) version information or date :-(
Please, if you publish guidance, especially if you are an influential company, include a date in your documents. I treat a guidance form 2016 differently than a guidance from 2023

Back to the recommendations. Most of the are solid but some stick out

  1. Maintain an 8-character minimum

That seem awfully short. states "Longer is better", the recomend 15+ characters and, wait for it Microsoft themself recommends 12 or better 14+ characters.

  1. Ban common passwords, to keep the most vulnerable passwords out of your system.

The NIST recommendation check against "commonly used and compromised passwords" considerably extends this!

Microsoft at other places recommends "Not a word that can be found in a dictionary or the name of a person, character, product, or organization."

  1. Educate your users not to re-use their password for non-work-related purposes.

Work related reuse is OK????

I would love to know if internally really follows these password rule. Or if they enforce a more strict set. If anyone knows about this, please let me know (but don't if this would gt you fired)

BTW, the other place were Microsoft recommends a different/stronger set of password rules is here (gain no date):
https://support.microsoft.com/en-us/windows/create-and-use-strong-passwords-c5cebb49-8c53-4f5e-2bc4-fe357ca048eb

  • All
  • Subscribed
  • Moderated
  • Favorites
  • microsoft
  • Durango
  • magazineikmin
  • mdbf
  • thenastyranch
  • khanakhh
  • rosin
  • Youngstown
  • ethstaker
  • slotface
  • modclub
  • kavyap
  • DreamBathrooms
  • everett
  • ngwrru68w68
  • JUstTest
  • InstantRegret
  • tacticalgear
  • GTA5RPClips
  • cubers
  • normalnudes
  • osvaldo12
  • tester
  • anitta
  • cisconetworking
  • megavids
  • Leos
  • provamag3
  • lostlight
  • All magazines