Why this matters
A good password policy gives staff simple, sensible rules that genuinely improve security. Old-style rules such as forced 30-day changes and complex character requirements tend to produce weaker passwords. Modern guidance focuses on length, uniqueness and MFA.
What you'll need
- A document template
- Agreement from management
Step-by-step instructions
Step 1
Set a minimum length
Require passphrases of at least 14 characters. Encourage four or more random words.
Step 2
Require unique passwords
Work passwords must not be used anywhere else, especially personal accounts.
Step 3
Provide a password manager
Supply an approved business password manager so staff can store and share credentials securely.
Step 4
Require MFA
State that MFA is required for all work accounts that support it, and that MFA codes must never be shared.
Step 5
Change only when needed
Require password changes when compromise is suspected, rather than on a fixed schedule.
Step 6
Cover shared and admin accounts
Shared credentials must be stored in the password manager and changed when someone with access leaves. Admin accounts must be separate from everyday accounts.
Step 7
Explain how to report problems
Tell staff exactly who to contact if they think a password has been exposed.
Summary
A short policy built on length, uniqueness, a password manager and MFA is easier to follow and far more effective than complexity rules.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.