<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Users forced to change password? in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1428#M1095</link>
    <description>&lt;P&gt;Yea for us too&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2023 13:25:22 GMT</pubDate>
    <dc:creator>jasoncrcsd</dc:creator>
    <dc:date>2023-10-19T13:25:22Z</dc:date>
    <item>
      <title>Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1418#M1090</link>
      <description>&lt;P&gt;So yesterday we had many many calls from users complaining they were forced to reset their passwords. We have them set to expire at 180 days but its unlikely all of these users happen to have all changed their pwd last 180 days ago. Could something have caused this?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 11:42:31 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1418#M1090</guid>
      <dc:creator>jasoncrcsd</dc:creator>
      <dc:date>2023-10-19T11:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1423#M1091</link>
      <description>&lt;P&gt;First the obligatory comment that you should stop doing that. Nobody should change a proper and not compromised password. Ever.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 12:05:29 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1423#M1091</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-10-19T12:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1424#M1092</link>
      <description>&lt;P&gt;Yes I know I've tried fighting that battle trust me. But I have a boss and... well you all know. I've even sent them the research so they know its not just me saying that.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 12:31:45 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1424#M1092</guid>
      <dc:creator>jasoncrcsd</dc:creator>
      <dc:date>2023-10-19T12:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1425#M1093</link>
      <description>&lt;P&gt;I agree with Kim. But, we run into the same issues with Cyber Insurance and our Financial Auditors requiring it.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 12:48:33 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1425#M1093</guid>
      <dc:creator>Dave_Burek</dc:creator>
      <dc:date>2023-10-19T12:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1426#M1094</link>
      <description>&lt;P&gt;Now today I have sub accounts prompting and those accontys do not have a psss exp date. Somethign is wrong in Google but they say nothing&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 13:04:19 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1426#M1094</guid>
      <dc:creator>jasoncrcsd</dc:creator>
      <dc:date>2023-10-19T13:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1428#M1095</link>
      <description>&lt;P&gt;Yea for us too&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 13:25:22 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1428#M1095</guid>
      <dc:creator>jasoncrcsd</dc:creator>
      <dc:date>2023-10-19T13:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1434#M1096</link>
      <description>&lt;P&gt;Not arguing, but curious why a proper and not-compromised account should not change their password?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 16:42:12 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1434#M1096</guid>
      <dc:creator>Kelly_McMahon</dc:creator>
      <dc:date>2023-10-19T16:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1441#M1097</link>
      <description>&lt;P&gt;Kelly,&lt;/P&gt;&lt;P&gt;Probability math. A strong password is just as likely to be brute-forced five minutes after it’s created as it would be after six months. It’s also why lottery, or other gambling numbers are never “due.”&lt;/P&gt;&lt;P&gt;So why needlessly annoy users? It makes them more resistant to valid security requests.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 23:10:08 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1441#M1097</guid>
      <dc:creator>MarkLoundy</dc:creator>
      <dc:date>2023-10-19T23:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1442#M1098</link>
      <description>&lt;P&gt;Because a good password can't be hacked (within reasonable time = hundreds/thousands of years), only leaked (compromised).&lt;/P&gt;&lt;P&gt;That means there is almost no security risk keeping a good password "forever".&lt;/P&gt;&lt;P&gt;Also, when forcing password changes, users keep making their passwords less secure, or have them on a post-it on their desk or directly on the computer. This is what all research shows, and exactly why NIST not only changed their policy, but outright says to avoid forced changes, unless compromised.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 07:51:57 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1442#M1098</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-10-20T07:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1443#M1099</link>
      <description>&lt;P&gt;That is where you have to put your foot down. They are wrong, and need to be told so, or they will keep recommending/forcing bad practice forever.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 07:52:54 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1443#M1099</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-10-20T07:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1444#M1100</link>
      <description>&lt;P&gt;That is strange, but afaik, you are so far the only one reporting the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 07:53:40 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1444#M1100</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-10-20T07:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1446#M1101</link>
      <description>&lt;P&gt;Yea it could be. its not really as big an issue as they are making it.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 15:40:36 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1446#M1101</guid>
      <dc:creator>jasoncrcsd</dc:creator>
      <dc:date>2023-10-20T15:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1448#M1102</link>
      <description>&lt;P&gt;I will say that NIST (if you're in the USA) doesn't even recommend password changes anymore in their guidelines and Microsoft hasn't in at least a decade or more. We've gone away from password changes unless we get notified of compromised accounts. Luckily our insurance as far as I'm aware doesn't have a clause around this.&lt;/P&gt;&lt;P&gt;I'd have to agree and also disagree with Kim because if the Insurance is dictating this, we you have a say. We can suggest things, but at the end of the day it's the Insurance that is going to be paying out based on their contract. It could also be that if you don't comply and change passwords X-days, the premiums may go up substantially which organizations (especially edu/nonprofits) cannot afford.&lt;/P&gt;&lt;P&gt;It's hard enough to find a Cyber Insurance provider as EDU is especially targeted. Our previous Cyber Insurer exited the EDU market completely and dropped all schools because Edu caused them to pay out so much money.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 18:34:09 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1448#M1102</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-10-20T18:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Users forced to change password?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1456#M1103</link>
      <description>&lt;P&gt;For what it's worth, our Auditors (not Cyber Security Insurance co) were requiring password changes until I took the time to point out to them that it was a dated practice.&lt;/P&gt;&lt;P&gt;I shared some of the resources on new best practices, and the following year they had removed the requirement.&lt;/P&gt;&lt;P&gt;So it may be worth trying if you hadn't.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But yeah, I certainly wouldn't count on getting them to change.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing a strong, un-compromised password is bad practice&amp;nbsp; -and may actually increase odds of bad password habits.&amp;nbsp; BUT - the reality is that most places/people still don't realize that their password HAS been compromised until it's too late. So I can still see the logic in just taking the oldschool "hammer" approach.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 19:05:58 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Users-forced-to-change-password/m-p/1456#M1103</guid>
      <dc:creator>Justin_W</dc:creator>
      <dc:date>2023-10-20T19:05:58Z</dc:date>
    </item>
  </channel>
</rss>

