Request for Assistance Regarding Password Security

Kanchana Jayathilake 20 Reputation points
2024-04-05T09:40:35.6033333+00:00

I'm writing to inform you about a recent security incident we encountered within our organization. Unfortunately, we experienced some insider phishing attacks that compromised certain email accounts. As a precautionary measure, we immediately reset the passwords for these compromised accounts. However, upon further investigation, we discovered that both the old and new passwords remain active for 180 minutes or more specially when sending the multiple mails, posing a potential security risk.

We kindly request your assistance in providing guidance on how we can effectively reduce the duration for which both passwords remain active. Any advice or recommendations you can offer would be greatly appreciated.

Regards

Exchange | Exchange Server | Management
Exchange | Exchange Server | Management

The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.

Exchange | Hybrid management
Exchange | Hybrid management

The administration of a hybrid deployment that connects on-premises Exchange Server with Exchange Online, enabling seamless integration and centralized control.

Exchange | Other
Exchange | Other

A powerful email and collaboration platform developed by Microsoft, designed to support enterprise-level communication and productivity. Miscellaneous topics that do not fit into specific categories.

0 comments No comments

1 answer

Sort by: Most helpful
  1. JimmyYang-MSFT 58,786 Reputation points Moderator
    2024-04-08T06:49:28.4833333+00:00

    Hi @Kanchana Jayathilake

    Regarding your question, it sounds like you are concerned about the duration for which both the old and new passwords remain active. I can suggest a few general best practices that may be helpful:

    1. Implement two-factor authentication: This adds an extra layer of security by requiring a second form of authentication, such as a code sent to a mobile device, in addition to a password.
    2. Use strong passwords: Ensure that all employees are using strong passwords that are difficult to guess or crack. This can include using a combination of uppercase and lowercase letters, numbers, and special characters.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.