- What are the best practices for password reset policy?
- How often should administrators and network users be required to change their password?
- When should a password be changed?
What are the best practices for password reset policy?
Best practices for password policy
Configure a minimum password length. Enforce password history policy with at least 10 previous passwords remembered. Set a minimum password age of 3 days. Enable the setting that requires passwords to meet complexity requirements.
How often should administrators and network users be required to change their password?
The local administrator password should be reset every 180 days for greater security and the service account password should be reset at least once a year during maintenance time.
When should a password be changed?
Cybersecurity experts recommend changing your password every three months. There may even be situations where you should change your password immediately, especially if a cybercriminal has access to your account.