Plus, if you're missing a requirement when trying to set your password, the easiest thing to do is just append the missing requirement at the end. Especially if it's punctuation, which naturally goes at the end of words/sentences anyway.
And yet, none of these requirements are visible on the login page! So I have no freaking clue what my password might actually be, and thus my typical login flow for these lesser used accounts is always going through the password reset flow. It's a joke.
I can practically date my old passwords (for unimportant things) by this, and/or how many times I forgot it and had to set a new, unique password.
azalea
> Your password needs to contain a number and a special character.
azalea1!
<word> <special char> <number>
Whereby word & special character are set in stone (easy to remember) and the number just increments with every change.
If only there was a way to allow more flexible demands on passwords within MS AD, things would improve so much.
Password > 14 characters and NOT listed in Pwned Passwords == allow for passphrase to be used "forever"
Password < 14 characters OR listed in Pwned Passwords == demand (regular|immediate) change.
Very decent source for Pwned Passwords https://haveibeenpwned.com/Passwords
edit: title is "You Should Probably Change Your Password! | Michael McIntyre Netflix Special" if you prefer to search on youtube yourself