Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Password Policy Is Still a Security Control

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2018, written in 2026 with the benefit of hindsight.

The short version: Most password rules produce predictable passwords like "Summer2018!", which attackers try first. In 2018, Microsoft introduced a way to block those commonly attacked passwords — a simple control many organizations still haven't turned on for their internal systems.

Why password policy still matters

Even with multi-factor authentication, passwords protect many systems: on-premises applications, VPNs, service accounts and anything not yet covered by MFA. Predictable passwords make those the weakest point.

Modern guidance has changed

The US National Institute of Standards and Technology now recommends checking passwords against lists of known compromised and common values, and avoiding forced periodic changes and arbitrary complexity rules, which push people toward predictable patterns.

Questions to ask your team

  • Do we block common and company-related passwords, both in the cloud and on-premises?
  • Do we still force password changes every 90 days without evidence of compromise?
  • Which systems still rely on passwords alone?
  • What is our plan to move to passwordless sign-in?

What good looks like

Banned password lists in place everywhere, longer passphrases encouraged, MFA on every system that supports it, and a roadmap to passwordless methods such as passkeys.

The decision

Ask whether banned password protection is enforced on your on-premises domain controllers, not just in the cloud. It is often a half-day project with immediate benefit.

azure ad password protection impactAzure AD Password Protection2018

More on this story