What should a modern password policy for a company look like?
You should prioritize long, unique credentials, block known compromised passwords, provide an approved manager, and require MFA. When permitted by the provider, phishing-resistant passkeys reduce reliance on passwords and codes that can be stolen.
Risks to review
- Forcing too frequent changes and causing predictable variations or written down passwords.
- Reuse the same credential in mail, administration, banking and external services.
- Save passwords in shared documents, unmanaged browsers or chats.
- Adopt passkeys without defining recovery, authorized devices and personnel exit.
Safe recommendations
- Require long, unique phrases, and block common or exposed passwords.
- Provide a business manager with documented access, recovery, and deregistration.
- Enable MFA and prioritize passkeys or security keys on supported accounts.
- Eliminate weak security questions and protect recovery channels.
- Review shared credentials and replace them with individual identities when possible.
- Train on phishing and establish an easy channel to report suspicious requests.
When to seek specialized help
- There are many shared accounts or it is not known who keeps the credentials.
- You want to deploy passkeys without a device and recovery policy.
- Unknown access, mass reuse or exposed credentials appear.
Reference sources
These public sources provide general good-practice guidance. They do not replace an assessment of your environment.

