And yet it is still the recommended practice for every IT department for pretty much all corps. Even AWS has their forced 90 password reset policy where you start to get reminders 15 days early so it's actually 75 days. Only at AWS, they don't force you into the password rotation flow at the end of the 90, they automatically lock the account. While that might make sense for inactive accounts, for accounts that have clicked the Not Now for 14 days should be taken to a change password screen instead. /rant