This is arguably even more impactful than NIST's upgraded password policy recommendations, because far too many in IT ignore modern #infosec thought on password policy (among other things) and just apply the Microsoft recs. #defaultsmatter https://arstechnica.com/gadgets/2019/04/password1-password2-password-3-no-more-microsoft-drops-password-expiration-rec/