7.3 Ensure that mobile devices are set to never expire passwords

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Ensure that users passwords on their mobile devices, never expire.

Rationale:

While this is not the most intuitive recommendation, research has found that when periodic password resets are enforced, passwords become weaker as users tend to pick something weaker and then use a pattern of it for rotation. If a user creates a strong password: long, complex and without any pragmatic words present, it should remain just as strong is 60 days as it is today. It is Microsoft's official security position to not expire passwords periodically without a specific reason.

Impact:

This setting should not cause a noticeable impact to users

Solution

To set mobile device management profiles, use the Microsoft 365 Admin Center:

Select Device Management under Admin Centers.

Select Devices, then under Policy select Configuration profiles

Review the list of profiles.

From there, go to the device policies page to remove any device security policies that expire passwords.

Default Value:

Password changes are not required by default

See Also

https://workbench.cisecurity.org/files/3729