How to Set a Secure Password Policy for Your Business
A good password policy doesn’t need to make life difficult for your staff.
The aim is simple: stop weak and reused passwords from becoming an easy way into your business.
Here are five things we recommend.
1. Don’t reuse passwords
Every important business account should have its own password.
If the same password is used for Microsoft 365, your accounts package and another online service, one breach could potentially expose access to several systems.
Use a password manager to create and securely store unique passwords rather than expecting staff to remember them all.
2. Use long passwords
Length matters.
Encourage staff to use long, difficult-to-guess passwords rather than short passwords with predictable substitutions such as:
P@ssword123
Avoid company names, people’s names, seasons, football teams and other information someone could easily associate with your business.
3. Don’t force unnecessary password changes
The old advice was to make everyone change their password every 30, 60 or 90 days.
That’s no longer considered good practice.
Microsoft recommends avoiding routine password expiry and instead changing passwords when there is evidence or suspicion that an account has been compromised.
Frequent forced changes can encourage people to choose predictable passwords or simply alter the last character.
Better approach:
Long, unique password
- Password manager
- MFA
- Change the password when compromise is suspected
4. Turn on Multi-Factor Authentication
This is arguably more important than making password rules increasingly complicated.
Multi-Factor Authentication (MFA) requires another form of verification when somebody signs in.
That means a criminal who obtains a user’s password still has another security barrier to overcome.
Prioritise MFA for everyone, but pay particular attention to accounts with greater access, including:
- Business owners
- Administrators
- Finance staff
- Microsoft 365 / Google administrators
5. Block obviously weak passwords
Microsoft 365
Microsoft Entra Password Protection automatically checks new and changed passwords against Microsoft’s global list of known weak passwords and variants.
If your Microsoft licensing supports it, you can also configure a custom banned password list containing terms specific to your organisation.
Good candidates include your:
Company name • Brand names • Product names • Local terms
This helps prevent staff choosing passwords that are technically compliant but extremely easy to guess.
One more thing: check your admins
Take two minutes now and identify who has administrator access to your Microsoft 365 or Google Workspace environment.
Ask yourself:
Does every one of those people genuinely need administrator access — and do they all have MFA enabled?
An administrator account is considerably more valuable to an attacker than an ordinary user account.
Your password policy checklist
Before you leave this page, check:
☐ Staff aren’t reusing business passwords
☐ Important accounts have long, unique passwords
☐ A password manager is available to staff
☐ MFA is enabled
☐ Weak and predictable passwords are blocked where possible
☐ Administrator accounts have been reviewed
☐ Passwords are changed immediately when compromise is suspected
Seven ticks? You’re in much better shape than most businesses.
Want to know how secure you really are?
Passwords are only one part of your cybersecurity.
MXcentral brings together security information from across your business so you can see what’s protected — and what needs attention — from one simple dashboard.
request your free MXcentral security demo→ MXCentral
Murray Thorpe
Cablers IT Services
23 years supporting businesses with IT and cybersecurity