About this interactive
A password policy can be strict and still make passwords worse. That is the counterintuitive idea at the centre of this activity, and it is why so many organizations still run policies that were considered best practice fifteen years ago. You are the new IAM analyst at TechKnowDJ, and the password policy you have inherited was written by an IT manager who left in 2022. Your job is to read it rule by rule and click every rule that weakens security or trains staff into bad habits. Nine are planted. Some are obvious once you look: MFA made optional for the admin accounts, which are the accounts attackers want most; a VPN that lets anyone guess passwords forever; a shared admin password kept in a spreadsheet. Others are rules that sound tough. Passwords that expire every 60 days teach people to count, so Summer2026! becomes Fall2026!. A rule demanding a capital, a number and a symbol is satisfied by Password1!, one of the most common passwords there is. Blocking paste sounds careful but stops the company's own password manager from working, so people shorten their passwords to something they can type. Password hints and security questions give attackers a way around the password entirely. And IT's own habits set the tone: reading the same starting password to a room full of new hires tells everyone that sharing a password is fine and that this is what a good one looks like. The rules that are fine matter just as much, because a good policy keeps them: single sign-on so staff need one strong password instead of twenty weak ones, MFA on every account, a short pause after repeated failed sign-ins, a long minimum length, checking new passwords against lists of breached and common ones, a company password manager, changing a password when there is evidence it has been compromised, regular password audits with retraining for repeat offenders, and a proper identity check before the help desk resets anything. Submit and every fault is explained with the behavior it causes and the rule that should replace it, following the lesson and current NIST guidance.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →