This practice is not recommended anymore, yet still found in many enterprises.

  • ObsidianZed@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    6 months ago

    Agreed. My last job, we were forced to change all service account passwords annually but our personal passwords every month or two.

    My current job has more domains and systems so I have so many more passwords with varying complexity and age requirements. I just set a calendar event for every four weeks (one expires just under 5 weeks) and change them all to the same generated password that meets all the common requirements and I save it in my password manager.

    So every four weeks, it’s seriously this hour+ long ritual for virtually no enhanced security reason.