The latest guidelines suggest that our focus should be on password length, not complexity. Length is the most important security factor, and passphrases are the simplest way to get your users to create (and remember!) longer passwords.
See also: QR codes exploited in new malware technique

Why passphrases win on every front:
Fewer resets. When passphrases are memorable, users stop writing them down on Post-it notes or recycling similar variations across all their accounts. Support requests decrease, which in itself should justify the change.
Better resistance to attacks. Attackers optimize for patterns. They try dictionary words with common substitutions (@ for a, 0 for o) because that's what humans do. A four-word passphrase completely bypasses these patterns—but only when the words are truly random and unrelated.
Under current guidelines, NIST was clear: prioritize length over forced complexity. The traditional 8-character minimum should really be a thing of the past.
See also: Akira ransomware compromises SonicWall VPN accounts protected with MFA

The Active Directory password policy needs three updates to properly support passphrases:
- Increase the minimum length. Move from 8 to 14+ characters. This accommodates passphrases without creating problems for users who still prefer traditional passwords.
- Remove forced complexity checks. Stop requiring capital letters, numbers, and symbols. Length offers better security with less friction with the user.
- Block compromised credentials. This is non-negotiable. Even the strongest passphrases don't help if they've already been leaked in a breach. Your policy should check submissions against lists of known compromised credentials in real time.
Passphrases are not a panacea, however. MFA still matters. Tracking compromised credentials still matters. But if you’re going to spend resources on password policy changes, here’s where you can spend them: higher minimums, simpler rules, and real protection against compromised credentials.
See also: How to create strong and easy passwords

Attackers are still stealing hashes and brute-forcing them offline. What has changed is our understanding of what really slows them down, so the next password policy should reflect that.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
