Low

Password expiration disabled

Checks if password expiration policy is disabled

Category
Password Policy
Default severity
Low
Rule key
CHECK_PASSWORD_EXPIRATION
Last updated

How to fix it

Consider enabling password expiration or implement passwordless authentication.

Further reading

Microsoft documentation →

Run this check on your tenant

EntraAnalyzer evaluates this rule automatically on every scan and emails you the results.

Get started — free first scan →