Cybersecurity

Why it's a good idea to replace passwords with passphrases

clock icon October 23, 2025

Changes to authentication often cause resistance. Here's how to reduce friction:

Start with a pilot group: 50–100 users from different departments. Give them the new guidelines and observe (without imposing) for two weeks. See: do they use well-known expressions? Do they cover the length?

Enter "warnings only"„: Users are alerted when their new passphrase is weak or compromised, but they are not locked out. This builds awareness without a support burden.

Only apply after measuring:

  • Percentage of accepted passphrases
  • Reduction of reset tickets
  • Detecting banned passwords from blocklist
  • User feedback about difficulties

Follow them as key performance indicators (KPIs) – they will show whether the policy works better than the old one.

Maintain with the right tools

The Active Directory password policy needs to be updated:

  • Increase the minimum length from 8 to a minimum of 14 characters. This allows for the use of passphrases without a problem for traditional users.
  • Remove complexity requirements – don’t require capital letters, numbers, and symbols. Length provides better security with less stress.
  • Block compromised passwords – this is critical. Even the strongest password is useless if it has already expired. Your policy should compare passwords to a database of expired passwords in real time.

SSPR (self-service password reset) makes the transition easier – users can change passwords without contacting the helpdesk.

Password auditing provides visibility into progress – which accounts are still using short passwords or common patterns, so that targeted support can be provided.

Tools like Specops Password Policy bring it all together: minimum lengths, blocking over 4 billion compromised passwords, integration with SSPR. Policies are synchronized with Active Directory and Azure AD, without additional infrastructure. The blocklist is updated daily.

What does this look like in practice?

Imagine a policy that requires a minimum of 15 characters and no complexity requirements. A user creates umbrella-coaster-fountain-sketch on their next shift. Specops checks if this password is in a database of expired passwords – it is clean. The user remembers it without a password manager because it consists of four visual, concrete words. They don’t reuse it because they know it is unique to that account.

Six months later – no reset request. No note on the monitor. No call to the helpdesk for a confused symbol. Nothing revolutionary – just effective.

The security you really need

Passphrases are not a silver bullet. Multi-factor authentication is still a must. So is monitoring for compromised credentials.

But if you're going to put effort into changing your password policy, put it into this: longer passwords, simpler rules, and real protection against password cracking.

Hackers are still stealing hashes and cracking them offline. What has changed is our understanding of what actually slows them down. Your next password policy should reflect this. Source: https://thehackernews.com

Join

Start your career transformation today

Are you ready to develop your IT skills and achieve your career goals? Enroll in our courses now and start learning from leading industry experts.

Start now
    0
    Selected courses
    Your cart is empty.