Loading...

Rethinking identity beyond passwords

Rethinking identity beyond passwords

Your password isn’t protecting you.

At least not in the way you think. Not anymore. We’ve built a whole mythology around passwords — how long they should be, how often they should change, what characters to include. We treat them like they’re the foundation of our digital security.

They’re not.

xkcd-authz Source: https://xkcd.com/1200/

Usually, I don’t run security workshops. Most of the time, I’m there to talk about AI strategy, automation and custom apps with Power Platform and Azure, licensing and governance. But still every single time someone will eventually ask about passwords. Usually in a side comment. Should we increase password length? or Is it okay to allow password managers? or even What is a reasonable password policy? IT forces us to change passwords every 6 weeks!

It’s like a reflex. And every time it comes up, I realize just how much confusion and outdated thinking still surrounds this topic. Most of the ideas we still cling to about password security are based on assumptions that stopped being relevant many years ago. We’re still designing policies to protect against brute-force attacks — as if that’s the main threat. But in the real world, that’s the last thing an attacker tries. Before anyone even considers brute-forcing your password, they’ll try credential stuffing (using leaked passwords from another site). They’ll phish you with a fake login page. They’ll deploy malware to log your keystrokes. They’ll trick you into giving it away — and nine times out of ten, that works.

That’s the real threat landscape. And none of it is stopped by making your password a few characters longer or swapping a for @ or - as we collectively all decided, once vendors made it mandatory that at least one character needs to be a special character - adding an ! at the end of our existing password. So no, I don’t really care whether your password is 12 or 16 characters. It’s good practice to avoid reuse and common phrases, sure. But password strength is no longer a meaningful line of defense. If your identity strategy starts and ends with make better passwords, you’re solving the wrong problem.

What does work?

1. MFA

Multi-factor authentication changes everything. It stops account compromise even if the attacker has your password. And the numbers don’t lie — Microsoft’s own data shows that enabling MFA prevents over 99% of identity-based attacks. It’s not just effective; it’s essential. That’s why Microsoft enforced MFA for all accounts. But we can go further. And frankly, we should.

2. Passwordless authentication

Passwordless authentication with FIDO2 keys, Windows Hello, authenticator app push approvals, certificate-based logins: these are harder, better faster, stronger and far more secure than any password ever was. They’re phishing-resistant by design. They eliminate the weakest link: the password itself. When someone logs in with a biometric, or a device-bound key, or a hardware token, there’s nothing for an attacker to guess, steal, or reuse. Of course, going passwordless requires planning. You need a phased rollout, support for fallback methods, alignment with your Conditional Access policies. But it’s achievable — and honestly, overdue. The guidance is there. The tooling is mature. And the risk of doing nothing is growing. So the next time passwords come up — and they will — this is the conversation we need to have.

Not about complexity requirements or expiration intervals. Not about special characters or clever passphrases.

But about what actually works. What actually stops breaches. What actually reflects the modern threat landscape.

It’s time to start treating passwords as the liability we’ve failed to let go of.

Published on:

Learn more
Luise Freese: Consultant & MVP
Luise Freese: Consultant & MVP

Recent content on Luise Freese: Consultant & MVP

Share post:

Related posts

You are holding GitHub Copilot Wrong!

Most developers think that one can’t really use GitHub Copilot wrong. There is a chat interface that lets you also choose a model, so th...

8 months ago

You are holding GitHub Copilot Wrong!

Part 0 showed why constant prompting, re-prompting, and steering GitHub Copilot feels fragile. Not because Copilot is unreliable, but because ...

8 months ago

Building a Multi-Hierarchy Ticket Classification System (Because Keywords Aren't Enough)

Look, I love a good keyword-based system as much as the next developer. They’re fast, predictable, and when your user says “VPN,&r...

8 months ago

Secretless cross-tenant dataverse access

Client secrets are like hiding your house key under the mat; easy to grab and impossible to audit. Certificates are just slightly better, beca...

10 months ago

How Azure CLI handles your tokens and what you might be ignoring

Running az login feels like magic. A browser pops up, you pick an account, and from then on, everything just works. No more passwords, no more...

10 months ago

How Dev Proxy teaches you to make your apps more resilient

I added Microsoft Dev Proxy to my Mermaid → Dataverse converter, because I wanted to test how it handled rate limits and API errors. What I go...

10 months ago

Building Azure functions that never store secrets — ever

What if your function could hit Microsoft Graph with no client secrets, no certs, and no Key Vault entries? That is exactly what a Managed id...

10 months ago

Introducing Mermaid to Dataverse Converter

Why diagrams matter (and why they usually fail us) Entity-Relationship Diagrams (ERDs) are the universal shorthand for talking about data mode...

11 months ago

It’s OK to be seen trying

It’s OK to be seen trying Somewhere along the way, we started believing that you’re only allowed to speak after you’ve figured everything out....

1 year ago

Stuck in pilot - Part 1: no foundations, no future

“We just need to test the AI. We’ll figure out the data later.” That sentence has quietly killed more AI pilots than any model failure ever ...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.