I don’t agree with that. Regular password rotation increases the opportunity for phishing attacks because people become used to sleep walking through it. And users are generally just adding one or two characters to the password anyway.
Instead, that energy is better spent on requiring strong passwords and people using password managers and two-factor.