CIO Brief: Password Policy Is Still a Security Control
Retrospective: this article looks back at events from June 2018, written in 2026 with the benefit of hindsight.
The short version: Most password rules produce predictable passwords like "Summer2018!", which attackers try first. In 2018, Microsoft introduced a way to block those commonly attacked passwords — a simple control many organizations still haven't turned on for their internal systems.
Why password policy still matters
Even with multi-factor authentication, passwords protect many systems: on-premises applications, VPNs, service accounts and anything not yet covered by MFA. Predictable passwords make those the weakest point.
Modern guidance has changed
The US National Institute of Standards and Technology now recommends checking passwords against lists of known compromised and common values, and avoiding forced periodic changes and arbitrary complexity rules, which push people toward predictable patterns.
Questions to ask your team
- Do we block common and company-related passwords, both in the cloud and on-premises?
- Do we still force password changes every 90 days without evidence of compromise?
- Which systems still rely on passwords alone?
- What is our plan to move to passwordless sign-in?
What good looks like
Banned password lists in place everywhere, longer passphrases encouraged, MFA on every system that supports it, and a roadmap to passwordless methods such as passkeys.
The decision
Ask whether banned password protection is enforced on your on-premises domain controllers, not just in the cloud. It is often a half-day project with immediate benefit.
- Azure AD Password Protection Preview (2018): Banning Bad Passwords in the Cloud and On-Prem Platform Changes
- How to Deploy Entra Password Protection to On-Premises Domain Controllers How-To & Hardening
- Custom Banned Password List Checklist for Entra ID How-To & Hardening