> Even AWS has their forced 90 password reset policy
This is a policy set by the organization. You can easily change it to longer in IAM (or disable it entirely).
This is a policy set by the organization. You can easily change it to longer in IAM (or disable it entirely).
Another AWS set of creds is SSO+2FA, and no longer has the rotating policy. It's like a breath of fresh air.
Turns out, just like TFA, several security audits I've been through all list the password rotation policy in them.