How to Create a Password Policy Employees Won’t Hate

The classic password policy — eight characters, a symbol, a number, forced changes every 90 days — is both widely hated and, according to most current security guidance, not particularly effective. It trains employees to write passwords on sticky notes or make trivial, predictable changes just to satisfy the requirement. Building a policy that’s genuinely secure and doesn’t make everyone’s life miserable takes a different approach.

Step 1: Rethink Complexity Requirements

Modern security guidance has largely moved away from forcing symbols, numbers, and mixed case in favor of length. A long passphrase — several unrelated words strung together — is both easier to remember and mathematically harder to crack than a shorter, “complex” password stuffed with substitutions anyone can guess, like swapping a letter for a similar-looking number. Set a minimum length of at least twelve characters and stop requiring the specific character-type combinations that made passwords hard to remember without making them meaningfully more secure.

Step 2: Drop Mandatory Periodic Changes

Forcing password changes every 90 days, absent any sign of compromise, is now widely considered counterproductive. Employees respond to forced changes by making minimal, predictable modifications — swapping a “1” for a “2” — which does little for actual security while creating real friction. Change passwords when there’s a specific reason to: a suspected compromise, a departing employee, evidence of exposure in a data breach. Otherwise, leave a genuinely strong password alone.

Step 3: Make Multi-Factor Authentication the Real Backbone

If there’s one policy change worth prioritizing over everything else, it’s this one. MFA reduces the risk of a compromised password actually leading to unauthorized access more than almost any other single control available. Roll it out everywhere sensitive data lives — not just email, but file storage, financial systems, and administrative accounts — and treat it as non-negotiable rather than optional for anyone with access to something worth protecting.

Step 4: Provide a Password Manager, Don’t Just Recommend One

Asking employees to remember dozens of unique, strong passwords without giving them a tool to manage that is setting the policy up to fail. A company-provided password manager removes the single biggest reason people reuse passwords across accounts in the first place — nobody can remember forty unique passphrases, but everybody can remember one strong master password protecting a vault that handles the rest.

Step 5: Ban Password Reuse Explicitly, and Explain Why

Make it explicit that work passwords should never be reused on personal accounts, and vice versa. This matters because breaches on completely unrelated services happen constantly, and reused passwords mean a breach anywhere becomes a potential breach everywhere. Most employees don’t reuse passwords out of carelessness — they do it because remembering unique passwords is genuinely hard, which is exactly why step four matters so much.

Step 6: Write the Policy in Plain Language

A password policy written in dense compliance language gets skimmed, not read. Write it the way you’d explain it to a new hire in person: here’s the minimum length, here’s why we use a password manager, here’s when MFA is required, here’s what to do if you think your account’s been compromised. Clarity gets followed. Legalese gets ignored.

Step 7: Explain the Why, Not Just the What

Employees follow security policies more consistently when they understand the actual reasoning, not just the rule. A brief explanation of how credential theft actually leads to real incidents — and why length matters more than complexity, why MFA matters more than either — turns a policy people tolerate into one they genuinely buy into.

Step 8: Revisit It as Guidance Evolves

Password security best practices have changed significantly over the past decade and will likely keep changing. Review your policy annually against current recommendations from reputable security bodies, and don’t be afraid to remove requirements that current research no longer supports, even if they’ve been standard practice for years. Consulting an outside managed IT services team during this review can be useful for benchmarking your policy against what’s actually working elsewhere.

A password policy that people actually follow protects a company far better than a stricter one that gets quietly circumvented the moment it becomes inconvenient.

Enjoyed this article? Share it!

Michael Morella
Written By

Michael Morella

98 Articles

Michael Morella is a managing editor at TSC Listens, where he leads events and special projects for the News team. He has overseen education and health coverage for the annual Best Colleges and Best Hospitals publications, covered politics and general news, managed the opinion section

Leave a Comment