Password Tips: Strong Passwords and Good Habits
Your work password protects your email, your files and your company's data. A few simple habits make it far harder for anyone to guess or steal, and they're easier than you might think. No special symbols or impossible-to-remember strings required.
In Short
- Make it long: a passphrase of four or more unrelated words beats a short, complicated password.
- One account, one password: never use your work password anywhere else.
- Keep it to yourself: we will never ask for your password, and neither will anyone legitimate.
- Approve only your own sign-ins in Microsoft Authenticator.
- Think it's been exposed? Tell us right away.
Make It Long: Use a Passphrase
Length matters more than anything else. A passphrase is a handful of random, unrelated words strung together. It's easy for you to remember and very hard for a computer to guess.
| Example | Verdict | Why |
|---|---|---|
Password1! |
Weak | One of the first passwords attackers try. |
Fall2026! |
Weak | Seasons, years and months are predictable. |
Buddy2015 |
Weak | Pet names, birthdays and family names are easy to find on social media. |
Tr0ub4dor&3 |
So-so | Looks complicated, but it's short, and swapping letters for numbers fools no one. |
Copper Lantern Rainy Kettle 7 |
Strong | Long, random words, easy to picture and remember. |
Your company's password rules always come first. If the system asks for a number, a capital letter or a symbol, add them to your passphrase, for example Copper-Lantern-Rainy-Kettle7.
What to avoid
- Names, birthdays, anniversaries, pets, sports teams or your company's name
- Keyboard patterns like
qwertyor123456 - An old password with a number changed at the end (
Summer1,Summer2...) - Anything you've used before, at work or anywhere else
One Account, One Password
When a website gets hacked, criminals try the stolen email and password combinations on other sites, including Microsoft 365. If your work password is the same as your password for a shopping site, a breach at that site is a breach of your work account.
- Never use your work password for anything else, especially personal accounts.
- Use a password manager to keep track of your other passwords, so each one can be unique. If your company provides one, use that; ask your manager or ask us which one is approved.
Keep It to Yourself
- We will never ask for your password, by email, phone, text or chat. Anyone who asks, even if they say they're from IT or Microsoft, is trying to trick you.
- Don't share your password with coworkers, not even to cover for you while you're out. If someone needs access to your email or files, we can set that up properly. See shared mailboxes or set up an automatic reply instead.
- Don't keep it on a sticky note on your monitor, under your keyboard or in an unlocked drawer.
- Only type it into pages you opened yourself. If an email link takes you to a sign-in page, close it and go to the site directly instead.
Your Second Lock: Microsoft Authenticator
Multi-factor authentication (MFA) means a password alone isn't enough to get into your account: your phone has to approve the sign-in too. It's your safety net if a password ever leaks.
- Approve only sign-ins you just started yourself. If you get a prompt out of the blue, tap Deny (or No, it's not me) and tell us. It may mean someone has your password.
- Never read an Authenticator number or code to anyone who calls or messages you.
- Getting a new phone? Move Authenticator before you trade in the old one: Getting a new phone: moving Microsoft Authenticator.
When to Change Your Password
- You think someone else knows it, you typed it into a suspicious page, or you approved a sign-in by mistake: contact us right away. We reset it and sign out any stolen sessions. See I already clicked a phishing link.
- Your computer asks you to: some companies require a new password every so often. See Computer & Network Password Resets.
- You forgot it: see Microsoft 365 Self-Service Password Reset.
Otherwise, a strong, unique password doesn't need to be changed just for the sake of it.