If you run a small business in the Upper Peninsula, you know the 90-day password rule. Every three months a little box shows up and tells you your password is about to expire. You invent a new one. You change the last number. You write it on a sticky note, lose the note, and get on with your day.

For years, that felt like security. It mostly is not. And the two groups who actually write the rules, Microsoft and the National Institute of Standards and Technology, have both walked away from it.

Where the rule came from

Calendar-based password changes are a leftover from a world of servers in a closet and logins shared around an office. The idea was simple. If a password gets stolen, changing it every 90 days limits how long a thief can use it.

That reasoning only holds together if you cannot tell when a password has been stolen. In that world, a calendar was the best alarm available. It was never a good alarm. It was the only one.

What Microsoft and NIST say now

NIST publishes the federal guidelines for digital identity. The current version, SP 800-63B Revision 4, finished in 2025, states plainly that systems "SHALL NOT require subscribers to change passwords periodically." It says a password should be forced to change only when there is evidence of compromise.

Microsoft agrees, and says so in its own admin screens. In the Microsoft 365 admin center, the checkbox for password expiration is labeled "Set passwords to never expire (recommended)." That word, recommended, is Microsoft's, not ours. Back in 2019, when Microsoft pulled expiration out of its Windows security baseline, it described periodic password expiration as "an ancient and obsolete mitigation of very low value."

Why the forced change backfires

Think about what you actually do when the box pops up. You do not invent something new and strong. You make a small, predictable edit. Spring2026 becomes Summer2026. Capital1 becomes Capital2. Security people have a name for that. It is not "a new password." It is the same password with a fresh coat of paint.

If your password was never stolen, expiring it accomplished nothing. If it was stolen, waiting for a calendar date to fix the problem makes even less sense. You would want to act now. So the forced change buys you very little either way, and it costs you a round of forgotten passwords, locked-out mornings, and sticky notes taped to monitors.

There is a smaller wrinkle too. Microsoft notes that people who only use the Outlook desktop app are not forced to reset their Microsoft 365 password until it expires in that app's cache, which can take days past the actual expiration date. A policy that leaks is not much of a policy.

The half you cannot skip

Here is the part that matters most, and the part that gets dropped when someone hears "stop expiring passwords."

Microsoft's recommendation to let passwords live is bundled with other things. A second check at login, called multi-factor authentication, for everyone. Longer passwords, with 14 characters as Microsoft's suggested minimum. And a check that rejects passwords already known to have been exposed in a breach.

The second check is the piece doing the real work. It is what stops a stolen password from being enough to get in. Nothing here is a reason to keep a short, weak password, or to reuse the same one at your bank. A long password that never rotates, plus a second check at login, is stronger than a short password you change on a schedule. The strength comes from the second check and the length, not from the calendar.

What to check on Monday morning

You do not need new software for most of this. You need to know where you stand. A short list of questions for whoever handles your email:

Ask whether the Microsoft 365 passwords for your team are set to expire on a schedule, and if so, why.

Ask whether the second check at login is switched on for everyone, including the person who says they do not need it.

Ask what the minimum password length is, and whether it is at least 14 characters.

Ask whether new passwords are screened against lists of known-breached passwords.

One caution before anyone flips a switch. If your email accounts are synced from an older server in your office, the expiration schedule may be set on that server and not in Microsoft 365 at all. Changing the cloud setting will not touch it. Find out which one is in charge first.

What this is not

This is not permission to be careless. It is not a reason to reuse a password across accounts. It is one setting, set once years ago and never looked at again, sitting inside a subscription you already pay for.

If you have never asked what your password policy actually is, that is the useful next step. Not a purchase. A question.

Call us at (906) 662-4481, or contact us for a free assessment. >Learn About Managed Services