Microsoft says more than 97% of the identity attacks it sees are password attacks: guessing, spraying common passwords across many accounts, and replaying logins stolen from other breaches. Strong passwords still matter, but the definition of a strong password changed in 2025, and a password on its own is no longer enough for anything important.
This guide covers the current password rules, which kinds of multi-factor authentication (MFA) hold up, and the Microsoft 365 change that lands on February 1, 2027. If your question is narrower, about whether a password vault itself is safe, our companion piece on how password managers protect your accounts answers it.
Key takeaways
- NIST now says length beats complexity: at least 15 characters for a password used on its own, with no forced character mixes and no scheduled changes.
- A business password manager is the only realistic way for staff to use a long, unique password for every account.
- Text message codes and simple push approvals can be phished or abused. Phishing-resistant sign-in such as passkeys blocks those attacks.
- Microsoft began making passkeys the default in Entra ID on September 1, 2026, and Microsoft-provided text and voice codes retire for most users on February 1, 2027.
Strong passwords: the old rules and the current ones
The National Institute of Standards and Technology (NIST) published the final version of its digital identity guidelines, SP 800-63B-4, in 2025. Several of its rules reverse advice that many offices still follow:
| Old habit | Current NIST guidance |
|---|---|
| 8 characters with a capital, a number and a symbol | At least 15 characters for a password used on its own. A password that is one part of MFA can be as short as 8, though longer is still better. |
| A forced mix of character types | Don’t require one. Complexity rules produce predictable passwords like Password1!. |
| A new password every 90 days | Force a change only when there’s evidence a password was compromised. Routine changes lead to Password2!, then Password3!. |
| Anything that meets the rules is accepted | Check new passwords against a list of common, expected and previously breached passwords. |
| Pasting blocked, password managers discouraged | Systems shall allow password managers and autofill. |
In practice, a passphrase of four or five unrelated words is long, strong and easy to type. Avoid names, birthdays, addresses, pet names, sports teams and keyboard patterns, and never reuse a work password anywhere else.
Nobody can remember 80 passphrases, so without a tool people reuse passwords or write them down. A business password manager generates and fills strong passwords, shares logins safely and keeps an audit trail. We provide a managed one for our clients.
How attackers get passwords now
Very few passwords are cracked by brute force anymore. Attackers mostly collect them:

- Fake Microsoft 365 or bank login pages capture what staff type, sometimes along with the MFA code.
- Credential stuffing tries usernames and passwords leaked from other sites against your email and apps. A reused password makes it work.
- Password spraying tries a short list of common passwords like Summer2026! against every account in your company, slowly enough to avoid lockouts. Our password spraying guide covers it in detail.
- Infostealer malware on a home or work computer copies saved browser passwords and session cookies and sends them off to be sold.
- MFA fatigue starts with a stolen password, then floods the user with push prompts until someone taps Approve just to make it stop.
Once inside a mailbox, an attacker can reset other passwords, read client files and send invoices from a real address, which is why sign-in security sits at the center of every cybersecurity program. We offer dark web monitoring to our clients, and when a staff email and password turn up in a breach dump, we notify the client so it can be changed.
Which MFA methods hold up
MFA asks for two different kinds of proof, such as a password plus your phone, a security key or a fingerprint. The methods differ a lot in strength:
| Method | Strength | Weak point |
|---|---|---|
| Text message or voice code | Better than a password alone | Can be phished, and SIM-swap scams can redirect it. NIST restricts its use, and Microsoft’s own guidance says it doesn’t recommend it. |
| Authenticator app with number matching | Stronger | Staff must type the number shown on screen, which defeats most MFA fatigue attacks. A convincing fake login page can still capture it. |
| Passkey, Windows Hello for Business or FIDO2 security key | Phishing-resistant | Tied to the real website, so a fake login page gets nothing. Microsoft says phishing-resistant MFA can block over 99% of identity-based attacks. |
For our clients, admin accounts use phishing-resistant sign-in such as FIDO2 security keys or passkeys, and everyone else approves sign-ins in an app with number matching. Admins can change everything else in the tenant, so they get the strongest method first.
The Microsoft 365 deadline for text codes
Feb. 1, 2027
The date Microsoft retires its own text message and voice codes for most Entra ID users. Passkeys became the default starting September 1, 2026.
A passkey replaces the password with a cryptographic key stored on your phone, computer or security key. You open it with a fingerprint, face or device PIN. There is nothing to type, so there is nothing to phish.
Starting September 1, 2026, Entra ID began prompting users who rely on text or voice codes to register a passkey. From February 1, 2027, Microsoft-provided text and voice delivery is retired for all users except Global Administrators and external users, who follow on July 1, 2027. After the deadline, anyone whose only MFA method is text or voice will be required to register a passkey before they can sign in. Organizations with a genuine need for text or voice can keep it through a paid third-party telephony provider.
If your staff still use text codes for Microsoft 365, plan the switch now, before a locked-out employee calls in February. Our post on whether passkeys are safe covers the rollout questions.
What regulators and insurers expect
- The FTC Safeguards Rule requires accounting, tax and financial firms to use MFA for anyone accessing customer information on their systems, unless the Qualified Individual approves an equivalent control in writing.
- HHS proposed updating the HIPAA Security Rule to require MFA, with limited exceptions. The proposal was published in January 2025 and has not been finalized as of this writing, but OCR already expects strong access controls in your risk analysis, and MFA is the easiest one to defend.
- Many cyber insurance applications ask directly whether MFA is enforced on email, remote access and admin accounts. A wrong answer can put a claim at risk.
We fill out those insurance security questionnaires for our clients, and missing MFA on some accounts is one of the gaps insurers commonly flag. Law firms and nonprofits face the same questions. Write your sign-in rules into your security policy and check them during your annual compliance review.
A checklist for this quarter
- Turn on MFA for every account that supports it, starting with email, remote access, banking, payroll and admin accounts.
- Move staff off text message codes to the Microsoft Authenticator app with number matching.
- Give admins phishing-resistant sign-in first, and use separate admin accounts for admin work.
- Roll out a business password manager and retire password spreadsheets.
- Update your password policy: 15 or more characters, no forced complexity, no scheduled expiration and a banned-password list.
- Block legacy sign-in methods that skip MFA.
- Teach staff to deny MFA prompts they didn’t start and report them right away.
The first three items close the doors attackers use most, and they cost little beyond time. If you aren’t sure how your users sign in today or how the February change will hit your team, book a 20-minute call and we’ll go through it with you.
FAQ
Frequently asked questions
Is a browser’s built-in password saving good enough?
For personal use it beats reusing passwords. For a business, a managed password manager is better because you can share logins safely, see an audit trail and remove access when someone leaves.
Sources: NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management, July 2025; Microsoft, Digital Defense Report 2025 summary; Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication; Microsoft Learn: How number matching works in Authenticator push notifications; Microsoft Learn: Microsoft Entra authentication overview, phishing-resistant methods; Microsoft Learn: NIST authenticator types and aligned Microsoft Entra methods; FTC: Safeguards Rule, what your business needs to know; HHS: HIPAA Security Rule NPRM fact sheet.




