Re: Why 42 Days
"Pa55w0rd" <Pa55w0rd@discussions.microsoft.com> wrote in message
news:B877C298-B1F2-4DE0-B8A4-F379AAD01D19@microsoft.com...
> Reviewing our domain security policy and wonder why microsoft recommend
> 42days as a "Maximum Password Age" ?
Remember that current thinking at MS is not 42 days, if there is such
a thing as current thinking (instead of 27zillion different thoughts).
42 days is 6 weeks.
After you take into account that people get warned about the need to
change 2 weeks before the expiration, and most people will change
it then instead of deal with dismissing a warning/offer at each login,
you end up with a one month password age before it gets changed.
Anything less and the pitchforks do indeed start to fly (at you), but
back then, MS was fairly new to the "get with the security awareness"
program, and evidently they felt that monthly passwords were about
as far as the curve could be pressed but wanted to seem aggressive
about forcing password changes.
In other words, whoever knows is probably well hidden in some
other area of MS product development now.
Roger