Microsoft will abandon regular mandatory password changes

Microsoft acknowledged in its blog that the basic security rules for Windows 10 and Windows Server, which require regular password changes, are essentially pointless. The fact is that the system requires users to create complex passwords, which are hard to remember. As a result, users often just change or add one character, making it easier to guess.

Microsoft will abandon regular mandatory password changes

According to the company, scientific studies have shown that periodic and mandatory password changes are ineffective and only work against those who already know the user's key. Therefore, it's better to change passwords as necessary rather than on a schedule, without waiting for them to expire.

As an alternative, Microsoft is discussing the mandatory use of banned password lists (goodbye to ‘qwerty’ and ‘123456’), multi-factor authentication, and biometric methods. However, the aforementioned options are currently proposed as examples, not strict guidelines.

The company stated that 'password expiration is an archaic and outdated method' of protection, making its use impractical. Microsoft suggests a more flexible strategy based on specific company requirements, although it has not provided details on when outdated mechanisms will be removed from the OS.

Overall, the company is gradually eliminating outdated and unnecessary elements from the system, but only in the new version. Thus, Redmond is following its strategy to transition as many users as possible to ‘10’. However, it still faces issues. Let’s remember that in the Windows 10 May 2019 Update there are issue disk name reassignment issues, which block the update to the latest version on PCs with connected external drives or SD memory cards.



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster