What should a modern password policy for a company look like?

You should prioritize long, unique credentials, block known compromised passwords, provide an approved manager, and require MFA. When permitted by the provider, phishing-resistant passkeys reduce reliance on passwords and codes that can be stolen.

Risks to review

  • Forcing too frequent changes and causing predictable variations or written down passwords.
  • Reuse the same credential in mail, administration, banking and external services.
  • Save passwords in shared documents, unmanaged browsers or chats.
  • Adopt passkeys without defining recovery, authorized devices and personnel exit.

Safe recommendations

  1. Require long, unique phrases, and block common or exposed passwords.
  2. Provide a business manager with documented access, recovery, and deregistration.
  3. Enable MFA and prioritize passkeys or security keys on supported accounts.
  4. Eliminate weak security questions and protect recovery channels.
  5. Review shared credentials and replace them with individual identities when possible.
  6. Train on phishing and establish an easy channel to report suspicious requests.

When to seek specialized help

  • There are many shared accounts or it is not known who keeps the credentials.
  • You want to deploy passkeys without a device and recovery policy.
  • Unknown access, mass reuse or exposed credentials appear.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.