You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: "Set the password expiration policy for your organization"
2
+
title: Set the password expiration policy for your organization
3
3
f1.keywords:
4
4
- CSH
5
5
ms.author: deniseb
6
6
author: deniseb
7
7
manager: dansimp
8
-
ms.date: 01/06/2026
8
+
ms.date: 02/19/2026
9
9
audience: Admin
10
10
ms.topic: how-to
11
11
ms.service: microsoft-365-business
12
12
ms.localizationpriority: high
13
13
ms.collection:
14
-
- Tier1
15
-
- scotvorg
16
-
- highpri
17
-
- M365-subscription-management
18
-
- Adm_O365
19
-
- Adm_TOC
20
-
- must-keep
21
-
- operations-pod
14
+
- Tier1
15
+
- scotvorg
16
+
- highpri
17
+
- M365-subscription-management
18
+
- Adm_O365
19
+
- Adm_TOC
20
+
- must-keep
21
+
- operations-pod
22
22
ms.custom:
23
23
- VSBFY23
24
24
- AdminSurgePortfolio
@@ -28,18 +28,17 @@ ms.custom:
28
28
- business_assist
29
29
- has-azure-ad-ps-ref
30
30
- azure-ad-ref-level-one-done
31
-
description: "Learn how an admin can set a password expiration policy for your business, school, or nonprofit in Microsoft 365 admin center."
31
+
description: Learn how to set a password expiration policy for your organization in the Microsoft 365 admin center. Configure passwords to expire or never expire and improve security.
32
+
#customer intent: As an IT administrator, I want to configure password expiration policies so that I can enhance the security of my organization's accounts.
32
33
---
33
34
34
35
# Set the password expiration policy for your organization
35
36
36
-
> Check out all of our small business content on [Small business help & learning](https://go.microsoft.com/fwlink/?linkid=2224585).
37
-
38
37
This article is for people who set password expiration policies for organizations, such as a business, school, or nonprofit organization, using Microsoft 365 for business.
39
38
40
-
As a user administrator, you can make user passwords expire after a certain number of days, or set passwords to never expire. **By default, passwords are set to never expire for your organization**.
39
+
As a user administrator, you can make user passwords expire after a certain number of days, or set passwords to never expire. **By default, passwords never expire for your organization**.
41
40
42
-
To avoid security risks associated with users setting weak passwords or reusing old passwords, we recommend enabling[multifactor authentication](../security-and-compliance/set-up-multi-factor-authentication.md). See [Password policy recommendations](../misc/password-policy-recommendations.md).
41
+
To avoid security risks associated with users setting weak passwords or reusing old passwords, enable[multifactor authentication](../security-and-compliance/set-up-multi-factor-authentication.md). See [Password policy recommendations](../misc/password-policy-recommendations.md).
43
42
44
43
## Before you begin
45
44
@@ -49,53 +48,57 @@ You must be a [user administrator](../add-users/about-admin-roles.md) to perform
49
48
50
49
To set user passwords to expire after a set amount of time, follow these steps:
51
50
52
-
1. In the Microsoft 365 admin center, go to the <ahref="https://go.microsoft.com/fwlink/p/?linkid=2072756"target="_blank">**Org Settings** page</a>.
51
+
1. Sign in to the [Microsoft 365 admin center](https://admin.cloud.microsoft/).
52
+
53
+
1. From the left navigation bar, select **… Show all**, and then select **Settings** to expand it.
54
+
55
+
1. Under **Settings**, select [**Org Settings**](https://admin.cloud.microsoft/?#/Settings/SecurityPrivacy) page.
53
56
54
57
If you don't have an appropriate role assigned, you won't see the **Org Settings** option. In this case, [Check administrator roles in your organization](../add-users/assign-admin-roles.md#check-administrator-roles-in-your-organization).
55
-
56
-
2. In the **Security and Privacy** tab, on the **Password expiration policy** page, uncheck the box to change the password policy.
57
58
58
-
3. Type how often passwords should expire. Choose a number of days from **14 to 730** and select **Save**.
59
+
1. In the **Org Settings** page, select the **Security and Privacy** tab.
60
+
61
+
1. In the **Security and Privacy** tab, select **Password expiration policy**.
62
+
63
+
1. In the **Password expiration policy** pane, clear the check box **Set passwords to never expire (recommended)**.
64
+
65
+
1. In the **Days before passwords expire** text box, enter how often passwords should expire. Choose a number of days from **14 to 730**, and then select **Save**.
59
66
60
67
> [!IMPORTANT]
61
-
> Password expiration notifications are no longer supported in the Microsoft 365 admin center and Microsoft 365 productivity apps.
62
-
68
+
> The Microsoft 365 admin center and Microsoft 365 productivity apps no longer support password expiration notifications.
69
+
63
70
## Important things you need to know about the password expiration feature
64
-
71
+
65
72
People who only use the Outlook app aren't forced to reset their Microsoft 365 password until it expires in the cache. This process can take days after the actual expiration date. There's no workaround for this configuration at the admin level.
66
73
67
74
## Prevent last password from being used again
68
75
69
-
If you want to prevent your users from recycling old passwords, you can do so by enforcing password history in on-premises Active Directory (AD). See[Create a custom password policy](/azure/active-directory-domain-services/password-policy#create-a-custom-password-policy).
76
+
To prevent users from recycling old passwords, enforce password history in Active Directory (AD). For more information, see[Create a custom password policy](/azure/active-directory-domain-services/password-policy#create-a-custom-password-policy).
70
77
71
-
In Microsoft Entra ID, the last password can't be used again when the user changes a password. The password policy is applied to all user accounts that are created and managed directly in Microsoft Entra ID. This password policy can't be modified. See [Microsoft Entra password policies](/azure/active-directory/authentication/concept-sspr-policy#password-policies-that-only-apply-to-cloud-user-accounts).
In Microsoft Entra ID, users can't reuse their last password when they change a password. This password policy applies to all user accounts that you create and manage directly in Entra ID, and it can't be modified. For more information, see [Microsoft Entra password policies](/azure/active-directory/authentication/concept-sspr-policy#password-policies-that-only-apply-to-cloud-user-accounts).
74
79
75
80
## New and federated domains
76
81
77
-
Password policies are set for each managed domain in your organization. If you add a new domain or convert a domain from *federated* to *managed*, you need to re-enable the organization password policy to update all domains again; otherwise, the new or converted domain keeps the default policy.
82
+
Set password policies for each managed domain in your organization. If you add a new domain or convert a domain from *federated* to *managed*, re-enable the organization password policy to update all domains. Otherwise, the new or converted domain keeps the default policy.
78
83
79
-
## Synchronize user passwords hashes from an on-premises Active Directory to Microsoft Entra ID (Microsoft 365)
84
+
## Synchronize user password hashes from on-premises Active Directory to Microsoft Entra ID
80
85
81
-
This article is for setting the expiration policy for cloud-only users (Microsoft Entra ID). It doesn't apply to hybrid identity users who use password hash sync, pass-through authentication, or on-premises federation like Active Directory Federation Services (ADFS).
82
-
83
-
To learn how to synchronize user password hashes from on premises AD to Microsoft Entra ID, see [Implement password hash synchronization with Microsoft Entra Connect Sync](/azure/active-directory/hybrid/how-to-connect-password-hash-synchronization).
86
+
This article explains how to set the expiration policy for cloud-only users (Microsoft Entra ID). It doesn't apply to hybrid identity users who use password hash sync, pass-through authentication, or on-premises federation like Active Directory Federation Services (ADFS).
To learn how to synchronize user password hashes from an on-premises Active Directory to Microsoft Entra ID, see [Implement password hash synchronization with Microsoft Entra Connect Sync](/azure/active-directory/hybrid/how-to-connect-password-hash-synchronization).
86
89
87
90
## Password policies and account restrictions in Microsoft Entra ID
88
91
89
-
You can set more password policies and restrictions in Microsoft Entra ID. Check out [Password policies and account restrictions in Microsoft Entra ID](/azure/active-directory/authentication/concept-sspr-policy) for more info.
92
+
You can set more password policies and restrictions in Microsoft Entra ID. For more information, see [Password policies and account restrictions in Microsoft Entra ID](/azure/active-directory/authentication/concept-sspr-policy).
90
93
91
-
## Update password Policy using PowerShell
94
+
## Update password policy using PowerShell
92
95
93
96
The `Update-MgDomain` cmdlet updates the password policy of a specified domain or tenant and indicates the length of time that a password remains valid before it must be changed.
94
97
95
98
To learn how to update password policy for a specific domain or tenant, see [Update-MgDomain](/powershell/module/microsoft.graph.identity.directorymanagement/update-mgdomain).
96
99
97
100
## Related content
98
101
99
-
[Let users reset their own passwords](../add-users/let-users-reset-passwords.md)
Copy file name to clipboardExpand all lines: microsoft-365/admin/setup/add-domain.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ f1.keywords:
5
5
ms.author: dansimp
6
6
author: dansimp
7
7
manager: dansimp
8
-
ms.date: 02/17/2026
8
+
ms.date: 02/19/2026
9
9
audience: Admin
10
10
ms.topic: how-to
11
11
ms.service: microsoft-365-business
@@ -90,11 +90,11 @@ To add a custom domain to Microsoft 365, select the tab based on your registrar'
90
90
>
91
91
> If your registrar supports **Domain Connect** but you prefer to manually verify domain ownership and manually add DNS records needed by Microsoft 365 services, select the **Manual** tab. If you decide to manually add DNS records, make sure you're familiar with how to properly add DNS records at your registrar. Incorrect DNS records can cause email and service outages.
0 commit comments