Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Password rotation is failing teams: what should replace it?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19841
Topic starter  

TL;DR: Frequent password rotation is often treated as a security baseline, but NIST guidance and related research show it can drive weaker passwords, sticky-note workarounds, and password reuse instead of real risk reduction, according to SecureAuth. The better model is compromise-driven change, supported by strong unique passwords, passwordless authentication, and risk-based access controls.

NHIMG editorial — based on content published by SecureAuth: mandatory password rotation every 30, 60, or 90 days

Questions worth separating out

Q: What should teams do instead of mandatory password rotation?

A: Teams should focus on strong unique passwords, password managers, compromise-driven resets, and phishing-resistant authentication.

Q: When does password rotation automation create more risk than it reduces?

A: It creates more risk when rotation is disconnected from inventory accuracy, service dependencies, and offboarding state.

Q: When should organisations force a password change?

A: Organisations should force a password change when there is evidence of compromise, such as leaked credentials, suspicious authentication activity, or confirmed account exposure.

Practitioner guidance

  • Retire blanket password rotation mandates Replace fixed 30, 60, or 90 day password-change rules with compromise-driven resets tied to evidence of exposure, suspicious use, or incident response triggers.
  • Strengthen password quality and recovery controls Require long unique passwords, support password managers, and ensure reset workflows do not create easy social-engineering paths back into human accounts.
  • Move high-risk populations toward passwordless access Prioritise phishing-resistant authentication for privileged users, remote staff, and high-value applications where password reuse creates the most exposure.

What's in the full article

SecureAuth's full article covers the operational detail this post intentionally leaves for the source:

  • The article's discussion of NIST-aligned password guidance and why periodic changes fell out of favour
  • Practical comparison of passwordless authentication, adaptive MFA, and compromise-driven password resets
  • SecureAuth's product framing for continuous verification and behavioural risk scoring in workforce access
  • Implementation context for organisations deciding how to replace legacy rotation policies

👉 Read SecureAuth's analysis of why frequent password rotation is losing favour →

Password rotation is failing teams: what should replace it?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19434
 

Mandatory password rotation is a policy artifact, not a security outcome. For human identity programmes, the control often satisfies process expectations while reducing practical authentication quality. When users are forced to change passwords on a timer, they create compensating behaviours that undermine the original intent, so the programme measures compliance rather than resilience.

A few things that frame the scale:

A question worth separating out:

Q: How do passwordless authentication and risk-based authentication differ?

A: Passwordless authentication removes the reusable secret from the login process, while risk-based authentication adjusts the level of challenge based on context and behaviour. One changes the credential model, the other changes the decision model. Many organisations need both if they want to reduce reliance on passwords without losing adaptive protection.

👉 Read our full editorial: Frequent password rotation weakens security more than it helps



   
ReplyQuote
Share: