MS.AAD.6.1v1 - User passwords SHALL NOT expire.

Information

The National Institute of Standards and Technology (NIST), OMB, and Microsoft have published guidance indicating mandated periodic password changes make user accounts less secure. For example, OMB-22-09 states, "Password policies must not require use of special characters or regular rotation."

Solution

1. [Configure the Password expiration policy to Set passwords to never expire](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/set-password-expiration-policy?view=o365-worldwide#set-password-expiration-policy).

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: microsoft_azure

Control ID: 76c3cdede8a1366ae9ed36603f790a0c539eae3468a646ac4b761319ec0142a6