Password Tips: Strong Passwords and Good Habits

Your work password protects your email, your files and your company's data. A few simple habits make it far harder for anyone to guess or steal, and they're easier than you might think. No special symbols or impossible-to-remember strings required.

In Short

  • Make it long: a passphrase of four or more unrelated words beats a short, complicated password.
  • One account, one password: never use your work password anywhere else.
  • Keep it to yourself: we will never ask for your password, and neither will anyone legitimate.
  • Approve only your own sign-ins in Microsoft Authenticator.
  • Think it's been exposed? Tell us right away.

Make It Long: Use a Passphrase

Length matters more than anything else. A passphrase is a handful of random, unrelated words strung together. It's easy for you to remember and very hard for a computer to guess.

Example Verdict Why
Password1! Weak One of the first passwords attackers try.
Fall2026! Weak Seasons, years and months are predictable.
Buddy2015 Weak Pet names, birthdays and family names are easy to find on social media.
Tr0ub4dor&3 So-so Looks complicated, but it's short, and swapping letters for numbers fools no one.
Copper Lantern Rainy Kettle 7 Strong Long, random words, easy to picture and remember.
Don't use the examples on this page. Make up your own words. A good trick: picture a silly scene (a copper lantern next to a kettle in the rain) and use the words from it.

Your company's password rules always come first. If the system asks for a number, a capital letter or a symbol, add them to your passphrase, for example Copper-Lantern-Rainy-Kettle7.

What to avoid

  • Names, birthdays, anniversaries, pets, sports teams or your company's name
  • Keyboard patterns like qwerty or 123456
  • An old password with a number changed at the end (Summer1, Summer2...)
  • Anything you've used before, at work or anywhere else

One Account, One Password

When a website gets hacked, criminals try the stolen email and password combinations on other sites, including Microsoft 365. If your work password is the same as your password for a shopping site, a breach at that site is a breach of your work account.

  • Never use your work password for anything else, especially personal accounts.
  • Use a password manager to keep track of your other passwords, so each one can be unique. If your company provides one, use that; ask your manager or ask us which one is approved.

Keep It to Yourself

  • We will never ask for your password, by email, phone, text or chat. Anyone who asks, even if they say they're from IT or Microsoft, is trying to trick you.
  • Don't share your password with coworkers, not even to cover for you while you're out. If someone needs access to your email or files, we can set that up properly. See shared mailboxes or set up an automatic reply instead.
  • Don't keep it on a sticky note on your monitor, under your keyboard or in an unlocked drawer.
  • Only type it into pages you opened yourself. If an email link takes you to a sign-in page, close it and go to the site directly instead.

Your Second Lock: Microsoft Authenticator

Multi-factor authentication (MFA) means a password alone isn't enough to get into your account: your phone has to approve the sign-in too. It's your safety net if a password ever leaks.

  • Approve only sign-ins you just started yourself. If you get a prompt out of the blue, tap Deny (or No, it's not me) and tell us. It may mean someone has your password.
  • Never read an Authenticator number or code to anyone who calls or messages you.
  • Getting a new phone? Move Authenticator before you trade in the old one: Getting a new phone: moving Microsoft Authenticator.

When to Change Your Password

Otherwise, a strong, unique password doesn't need to be changed just for the sake of it.

Think your password has been exposed? Submit a support request right away.
Was this article helpful?