If your company is anything larger than tiny and you are using Microsoft Office 365 or Azure, you will almost certainly run into a situation in which you want to a few user account set to not expire. Perhaps they are service accounts, or they are accounts that contractors rarely use.
Why Microsoft Says User Passwords Should NOT Expire
You might be surprised to find that Microsoft’s official position is that you should not have your Microsoft 365 or azure accounts expire:
Password expiration requirements do more harm than good, because these requirements make users select predictable passwords, composed of sequential words and numbers that are closely related to each other. In these cases, the next password can be predicted based on the previous password. Password expiration requirements offer no containment benefits because cybercriminals almost always use credentials as soon as they compromise them.
https://learn.microsoft.com/en-US/microsoft-365/admin/misc/password-policy-recommendations?view=o365-worldwide&WT.mc_id=365AdminCSH_inproduct#password-expiration-requirements-for-users
How to Set ALL Microsoft Office User Account Passwords To Expire or Not
- Sign into https://portal.office.com
- Click the ADMIN link (bottom of the left rail)
- Click SHOW ALL (on the left menu)
- Expand SETTINGS
- Click ORG SETTINGS
- Click SECURITY & PRIVACY tab along the top
- Click PASSWORD EXPIRATION POLICY
- Click the SET PASSWORDS TO NEVER EXPIRE checkbox
- Set the number of days between password resets
How To Set a Specific Microsoft User Account to Not Expire
- Open a PowerShell (or Windows Terminal) as an Administrator
- Enter
Install-Module MSOnline
- Enter
Connect-MsolService
- Sign in to the Microsoft Office 365 / Azure account
- OPTIONAL: Enter
Get-MsolUser -UserPrincipalName User@EmailAddress.com
- This will display some user account information
- Enter
Set-MsolUser -UserPrincipalName User@EmailAddress.com -PasswordNeverExpires $true
- Enter
$user = Get-MsolUser -UserPrincipalName "user@domain.com" | Select-Object UserPrincipalName, PasswordNeverExpires, WhenCreated, LastPasswordChangeTimestamp
$user
- This will display when the account was created, when the password was last changed, and if it is set to not expire
0 Comments