The forced password change seems to be popular with enterprise software managed by a corporate IT department. A favorite policy they enforce is something like the following..."You must change your password every 30 days. Your new password must be different than your last 8. It must contain at least one number and a mix of upper and lower case letters. It cannot be more than N characters in length." It's kind of ridiculous and counter productive in that it destroys an otherwise sensible strategy like the one you proposed (referring to your first comment) and in its place you get employees doing silly things like making their passwords Password1, Password2, Password3, etc with each successive forced reset.