Changing user passwords regularly is an excellent security practice, since it shortens the time an attacker can use stolen identity credentials. Expiration times for passwords should be driven by the risk level of the data being protected and the needs of the business. Passwords for access to high-risk data should be changed more regularly.
It's also important to strike a balance between blocking malicious access and driving users crazy with short expiration periods. Thirty days is considered a fairly short expiration time, but may be just right for the level of data protection required.
The starting point for existing users will be when their accounts are enrolled in the Active Directory system. If the expiration date in the GPO on a domain with existing users is going to be changed, the clock starts ticking the day the change is made. Existing users will only be prompted to change their passwords 30 days after that date. If they change their passwords before the 30-day period ends, the counter starts at that point for the new password. In that case, the next time they'll be prompted to change their password will be in 30 days after that new date.
Dig Deeper on Password management and policy
Related Q&A from Joel Dubin
Learn about the purpose of CAPTCHA challenges that enable websites to differentiate bots from authentic users to stop spammers from hijacking forums ... Continue Reading
Proper planning is at the top of the list for single sign-on best practices, but it's important to get enterprise SSO implementations off to a good ... Continue Reading
After a server room door has been compromised, finding a more secure solution is of utmost importance. Learn how to choose a server room door that ... Continue Reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.