IT department: ”A clear telltale sign of phishing is the sense of urgency. Official IT department email will never panic you into clicking strange links”
Also IT department: ”YOUR PASSWORD IS EXPIRING IN 24 HOURS!!! CLICK THIS STRANGE LINK NOW TO RESET YOUR PASSWORD!!!”
We simply don’t expire passwords regularly. We have Entra require a reset if it sees something suspicious. Other than that and manual “reset because suspicious”, your password can last forever.
We did 30 days, 15 days, one week, and 24 hours. And still, we’d have users get locked out for not changing their password or calling us in a panic because they only saw the 24hr notif. We switched over to only requiring changes when entra saw something fishy, which definitely lowered stress levels.
Exactly right. And the reasoning here is that the IT department is in no rush because they don’t care if your password expires, so what.
At some point the password will fail to work and you’ll be prompted to pick a new one. Either you’ll update it and log in, or you won’t, IT doesn’t care.
IT department: ”A clear telltale sign of phishing is the sense of urgency. Official IT department email will never panic you into clicking strange links”
Also IT department: ”YOUR PASSWORD IS EXPIRING IN 24 HOURS!!! CLICK THIS STRANGE LINK NOW TO RESET YOUR PASSWORD!!!”
We simply don’t expire passwords regularly. We have Entra require a reset if it sees something suspicious. Other than that and manual “reset because suspicious”, your password can last forever.
We did 30 days, 15 days, one week, and 24 hours. And still, we’d have users get locked out for not changing their password or calling us in a panic because they only saw the 24hr notif. We switched over to only requiring changes when entra saw something fishy, which definitely lowered stress levels.
24 hours, my IT department sends them out at 28 days!
It’s so stupid, and they still write the email as if it’s happening immediately.
Exactly right. And the reasoning here is that the IT department is in no rush because they don’t care if your password expires, so what.
At some point the password will fail to work and you’ll be prompted to pick a new one. Either you’ll update it and log in, or you won’t, IT doesn’t care.
Wait, IT was supposed to care at some point?