Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› How should organisations build stronger passwords for user…
Authentication, Authorisation & Trust

How should organisations build stronger passwords for user accounts?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Authentication, Authorisation & Trust

Organisations should require passwords that are long, unique, and difficult to guess. A practical baseline is at least 12 characters, combined with uppercase and lowercase letters, numbers, and symbols. Teams should also block common passwords, avoid personal information, and enforce unique passwords for each account so one breach does not expose multiple services.

What makes a stronger password in practice?

A stronger password is one that is long enough, unpredictable enough, and different enough from anything a person could reasonably guess or reuse. Length matters most because it raises the cost of brute force attacks, while mixed character sets add another layer of entropy when implemented well. Stronger passwords also avoid names, dates, company terms, and predictable patterns.

The practical goal is not to make passwords “complex” in a cosmetic sense, but to make them resistant to guessing and reuse at scale. A password policy should therefore favour length first, then block known weak choices, and finally ensure each account gets a unique secret so a compromise in one place does not become access everywhere.

For organisations that want a clearer baseline, current guidance from identity practice and NIST SP 800-63 Digital Identity Guidelines supports moving away from brittle composition-only rules and toward passwords that are long, user-memorable, and screened against weak or breached choices. That approach is more effective than relying on symbols alone.

How should policy shape password strength rules?

Policy should make the acceptable password space hard for attackers to predict and easy for users to follow consistently. Requiring at least 12 characters is a sensible floor for most user accounts, and longer passphrases are even better when the system supports them. Organisations should also reject obviously weak credentials, repeated characters, keyboard walks, and passwords built from personal or corporate details.

Character variety still has value, but it should be treated as a supporting requirement, not the whole strategy. A password like a long passphrase with mixed characters can be stronger than a short but “complex” string. The real test is whether an attacker can guess or enumerate it quickly, not whether it satisfies a checkbox pattern.

This is where a password policy becomes more than a formatting rule. It should also prevent reuse across accounts, because a unique password on each account limits blast radius when one service is breached. That principle is reinforced by Human vs Non-Human Identity, which highlights how reused credentials and shared access paths create avoidable governance and recovery problems across both people and machine access.

What controls make stronger passwords actually work?

Even good password rules fail if the surrounding controls are weak. Organisations should pair password strength requirements with blocklists for common and breached passwords, rate limiting on authentication attempts, MFA where appropriate, and monitoring for repeated failed logins or credential stuffing patterns. Without those controls, a technically strong policy may still be undermined by attack volume or user workarounds.

Password hygiene also depends on lifecycle discipline. When passwords are reset, recovered, or shared informally, the organisation often loses confidence in who knows the secret and where it was exposed. That is why secret reuse, ad hoc resets, and unmanaged shared accounts are security issues, not just help desk issues.

Modern attacks regularly exploit weak or reused credentials as an initial access path. The Ivanti Connect Secure exploitation 2024 case is a reminder that credential exposure can quickly become broader account compromise when passwords or adjacent secrets are harvested. Password strength is only one part of the control stack, but it is the part that often determines whether a stolen secret is immediately useful.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines modern password guidance for user authentication and weak-secret screening.
Recommendation — Adopt length-first password rules and screen new secrets against weak or breached choices.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCovers password lifecycle, strength, and management controls for user authenticators.
IA-2 — Identification and Authentication (Organizational Users)Applies because the question is about authenticating user accounts with stronger passwords.
Recommendation — Enforce authenticator quality, rotation, and reuse protections for user accounts. Require effective authentication controls for organizational user accounts.
CIS Controls v8CIS-5 — Account ManagementSupports account and password management practices that reduce credential misuse and reuse.
Recommendation — Standardize account controls that block weak and reused passwords.
ISO/IEC 27001:2022A.5.17 — Authentication informationAddresses management of authentication information, including password handling and protection.
Recommendation — Protect authentication information and apply secure password handling rules.

Practitioner Guidance

What to prioritise: Set a minimum length policy first, then add breached-password blocking and reuse prevention. If your current standard still focuses mainly on symbol composition, you are optimising the wrong failure mode.

What to verify: Confirm that your identity system accepts long passphrases, checks new passwords against known weak choices, and prevents the same password from being used across multiple accounts in the same environment. Test both registration and reset flows, because that is where weak enforcement often reappears.

Common mistake: Treating password complexity as a substitute for uniqueness. A strong-looking password that is reused across services still creates a single point of failure after one breach.

Practitioner takeaway: The strongest password policy is the one that reduces guessing, blocks known-bad choices, and limits reuse, because those three controls matter more in practice than cosmetic complexity rules.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org