https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Getty Images

Login Box - Username Administrator and Password in Internet Browser on Computer Screen

Microsoft’s Password Policy Best Practices Might Be Counterintuitive

  • Written by Brien Posey
  • January 14, 2020
Take human nature into consideration rather than sticking to the status quo.

From IT Pro Today

Throughout most of my 30-year IT career, the most basic password policy best practices have remained largely unchanged. While there is something to be said for consistency, the idea that certain practices have been recommended for three decades or more is a bit unsettling to say the least. When an industry holds onto a practice for such as long time it begs the question of whether that practice is outdated. One also has to question whether some of the basic security best practices that have been in place for what seems like forever might have been misguided from the very beginning.

Microsoft recently drew a mixture of praise and sharp criticism when the company announced that it no longer recommends periodic password changes. This announcement garnered a lot of attention, but there are other aspects of Microsoft’s current password recommendations for Office 365 that might best be described as counterintuitive. These include:

  • Maintain an eight-character minimum length requirement. (Longer isn’t necessarily better.)
  • Don’t require character composition requirements.
  • Don’t require mandatory periodic password resets for user accounts.

So, as you can see, Microsoft’s password policy best practices longer recommend periodic password changes or the use of special characters. Microsoft has even gone so far as to state that longer passwords are not necessarily better. So, what gives?

According to Microsoft, rules have a way of normalizing passwords. “Normalizing” refers to the practice of taking an input string and converting it into a standardized format. When a user enters a phone number into a VoIP phone, for instance, the user might enter a long string of numbers (8005551234), they might use dashes (800-555-1234), or they might even use parentheses and dashes combined ((800) 555-1234). As such, a VoIP application will typically use normalization techniques to convert the user’s input – whatever it may be – into a standardized format that the underlying software can use.

Password rules do the same sort of thing to passwords. Suppose that an organization requires passwords to be at least eight characters in length, contain at least one uppercase and at least one lowercase character, a special symbol, and at least one number. People who know these rules can use what they know about the organization’s password requirements to automatically eliminate out a lot of potential passwords. For example, a password cracker can be configured to automatically ignore any potential password with fewer than eight characters. It can also rule out any string that uses all lowercase letters or all numbers.

The previously referenced Microsoft document also mentions that it’s critically important to take human nature into account when devising a password policy. If, for example, a password policy requires the use of a capital letter, then there is a really good chance that a user will use a capital letter as their password’s first character. After all, we have all been conditioned from an early age to start sentences with a capital letter and to capitalize the first letter of proper nouns.

As for no longer requiring periodic password resets, Microsoft mentions that it can be easy for someone to guess a password based on the password that was previously used. When required to periodically change passwords, users have a tendency to use password transformations as a way of making the new password easier to remember. These password transformations might include things like incrementing a number at the end of a password or perhaps embedding the month and year into the password and using that as the basis for the password transformation.

The University of North Carolina at Chapel Hill actually has some interesting evidence to back this idea up. In a study, researchers were given access to about 10,000 accounts that were no longer in use (such as accounts belonging to former students). The researchers were supplied with hashes for the accounts’ previously used passwords, and in the span of several months had cracked a large percentage of those passwords.

The researchers then tried to guess the accounts’ current passwords based on the previously used passwords. The researchers were able to guess the current password within five guesses for 17% of the accounts. In those cases, knowing a users’ previous passwords made it easy to guess their current passwords.

It seems inevitable that passwords will eventually be replaced by biometric and other multifactor authentication technologies. For now, though, it’s important to take human nature into consideration when formulating password policies rather than simply accepting the static quo that has been in place for decades.

Tags: MSPs Endpoint MSSP Insider Security Training and Policies

Most Recent


  • Security Patch
    The Gately Report: Live Patching Beneficial Tool for MSSPs, CISA Launches Early Ransomware Notification
    Also, the number of ransomware victims skyrocketed last month compared to January.
  • Making Waves
    8 Channel People Making Waves This Week at Lumen, Accenture, Amazon, Canalys, More
    Cisco led a “crowded” secure access service edge (SASE) market in terms of revenue in 2022, experts said.
  • network in the cloud
    Fortinet, Huawei, Palo Alto, VMware Lauded in Gartner Peer Insights SD-WAN Study
    Thousands of customers have weighed in on how their SD-WAN vendors have performed.
  • Do AWS, Azure, Google, Oracle, Others, Have Too Much Market Power?
    The FTC, concerned about cloud vendors’ sway over customers, is seeking public comment.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • DevSecOps
    ServiceNow, Microsoft Set to Deliver Broad SecOps Integration
  • Dunce Cap Businessman
    Tired of MSSPs ‘Failing,’ Nuspire Debuts Platform to Combat Cyberattacks
  • Malicious hacker at computer with code
    FragAttacks Wi-Fi Vulnerabilities Pose Widespread Threat to Individuals, Businesses
  • Colonial Pipeline Just the Latest Victim in Darkside Ransomware Crime Spree

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

The Gately Report: Live Patching Beneficial Tool for MSSPs, CISA Launches Early Ransomware Notification

March 27, 2023

8 Channel People Making Waves This Week at Lumen, Accenture, Amazon, Canalys, More

March 24, 2023

National Women’s History Month: Channel Women Have Stories to Tell

March 24, 2023

Industry Perspectives

View all

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

Channel people making waves include: @jmcbain, @NetworkMoe, @ajassy, @JulieSweet, @Elvia_Valdes_M, @GovITDave… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

We delve into AI impacting the channel, this week featuring @nvidia, @GoTo, @twilio and more.… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

[email protected]_Inc's Peer Insights are a treasure trove for partners looking to sell #SDWAN. dlvr.it/SlRDmk https://t.co/oElLXzOIbb

March 24, 2023
ChannelFutures

#CPExpo preview: @GlobalIndirect of @AryakaChannel with a preview of the next phase of the company's channel progra… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

U.S. competition regulators want to know if @AWSCloud, @Azure, @GoogleCloud, @OracleCloud hold too much market powe… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

📣 Join us on April 13th to hear from the 2023 Channel Influencers and get their insights on the state of the channe… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

#CPExpo preview: Learn about why @USWired accepted an #acquisition deal and what partners should look for in an M&A… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

.@Veeam lays off 200 workers to increase efficiency. #backupandrecovery dlvr.it/SlQWZW https://t.co/QTJx1NX69q

March 24, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X