It's one of the updated NIST recommendations, I don't recall which one but it specifically calls out no password cycling for MFA protected accounts.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments