This practice is not recommended anymore, yet still found in many enterprises.

I am once again asking you to change your password
you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 2 years ago

It's one of the updated NIST recommendations, I don't recall which one but it specifically calls out no password cycling for MFA protected accounts.

  • source
  • parent