This practice is not recommended anymore, yet still found in many enterprises.
It's one of the updated NIST recommendations, I don't recall which one but it specifically calls out no password cycling for MFA protected accounts.
Only the hottest memes in Cybersecurity
It's one of the updated NIST recommendations, I don't recall which one but it specifically calls out no password cycling for MFA protected accounts.