This is arguably even more impactful than NIST's upgraded password policy recommendations, because far too many in IT ignore modern thought on password policy (among other things) and just apply the Microsoft recs.

