Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What are the signs that a complex password…
Authentication, Authorisation & Trust

What are the signs that a complex password policy is making security worse instead of better?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Authentication, Authorisation & Trust

A complex password policy is usually backfiring when users struggle to remember passwords, start writing them down, or choose predictable patterns to satisfy the rules. Those behaviours weaken actual security even if the policy looks stricter on paper. If the policy creates more memorisation burden than protection, length based passwords are usually the better control.

When the rules are too hard, what changes in user behaviour?

The clearest warning sign is that people start optimising for compliance with the policy instead of for actual account safety. If passwords become harder to remember, users compensate with workarounds, such as reusing patterns, writing them down, or making tiny edits to a base password. That means the policy is increasing friction without increasing resistance to real attack paths.

A second sign is that the policy drives a measurable rise in help desk resets, repeated lockouts, or password reset requests. Those are not just service issues, they are evidence that the control is pushing users toward insecure recovery behaviour and predictable shortcuts. When the policy is the main reason people cannot log in cleanly, the control is probably too complex for the environment.

A third sign is that passwords become more rule-shaped than entropy-shaped. If users are forced into a narrow formula, they often create passwords that satisfy the checklist but remain guessable because they follow the same character substitutions, capitalisation habits, or appended digits.

Why does complexity often reduce real password strength?

Complexity rules often fail because they try to control memorability with arbitrary constraints. The result is usually a human workaround, not stronger authentication. In practice, long passphrases and blocklisting against known-bad choices usually provide better security than demanding a mixture of symbols, numbers, and case changes that users can barely remember.

This is where Password Security and Password Manager Guide is the most directly useful reference, because it connects policy design to the behaviours that actually weaken or strengthen passwords, including reuse, breached passwords, and password manager adoption.

Complexity also invites predictable adaptation. People learn to satisfy the rule set with the smallest possible mental effort, which means the policy can end up standardising passwords across a workforce rather than diversifying them. The stricter the memorisation burden, the more likely users are to choose a pattern they can repeat under pressure.

What should practitioners look for before they trust the policy?

The best indicator is whether the policy improves resistance to guessing and reuse without increasing recovery risk. If the policy forces frequent resets, creates support debt, or produces obvious user workarounds, it is probably harming the overall security posture. A good policy is the one that users can follow consistently while still producing passwords that are hard to predict and hard to reuse.

Practitioners should also check whether the policy is aligned with modern authentication guidance rather than legacy complexity habits. Modern guidance increasingly favours length, screening against known-compromised values, and password managers over artificial composition rules. A policy that still treats symbol counts as the main defence is usually optimising for appearance, not resilience.

For implementation detail, NIST SP 800-63 Digital Identity Guidelines is the most relevant external benchmark for judging whether the policy reflects current authenticator guidance. If the policy conflicts with that guidance, it deserves review before it causes further user friction.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesGuides modern password policy toward length and compromise screening.
Recommendation — Align password rules with current authenticator guidance and reduce reliance on composition complexity.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCovers authenticator lifecycle controls that shape password handling and recovery.
Recommendation — Manage password issuance, change, and recovery to minimise weak workarounds and reuse.
CIS Controls v8CIS-5 — Account ManagementSupports account and authenticator practices that reduce insecure password behaviour.
Recommendation — Standardise account controls to cut reset-driven workarounds and predictable password patterns.
ISO/IEC 27001:2022A.5.15 — Access controlSupports access policy choices that must balance usability and authentication strength.
Recommendation — Review access rules so they improve assurance without creating avoidable user bypass behaviour.

Practitioner Guidance

What to prioritise: Treat user behaviour as the control test. If a policy leads to password reuse, note-taking, predictable patterns, or excessive reset volume, the policy is degrading security even if it looks stricter on paper.

Decision rule: If a password rule increases memorisation burden more than it increases resistance to guessing or reuse, simplify it and favour longer passwords plus screening against compromised values.

What to verify: Check whether the organisation can evidence lower reuse, fewer predictable patterns, and fewer recovery events after the policy change. If those signals move the wrong way, the policy needs redesign, not more user training.

Common mistake: Equating more character classes with better security. That approach often produces brittle passwords and worse outcomes than a simpler policy that users can actually sustain.

Practitioner takeaway: A password policy is too complex when it changes user behaviour in ways that create weaker real-world secrets, because the control is then optimising for compliance theatre rather than access security.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org