Should you still force password changes every 90 days in 2026? | Edward Kiledjian

Forcing periodic password changes every 90 days provides little security benefit and often results in weaker credentials, as modern guidelines from NIST and Microsoft recommend changing passwords only upon evidence of compromise. Organizations should instead prioritize phishing-resistant MFA, passkeys, and breached-password screening to effectively secure accounts.

Edward Kiledjian @ekiledjian