> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/user-password-never-expires.md).

# User Password Never Expires

Detects user accounts configured so their password never expires. Long-lived passwords increase the window for credential theft, reuse, and offline cracking, especially for privileged or service-connected accounts.

**Recommended Actions**

Disable Password Never Expires where possible and align the account with your standard password rotation policy. Review the account's privileges and rotate the password if its long-lived credential may have been broadly exposed.

**Compatibility**

[Microsoft Active Directory](/integrations/microsoft-active-directory.md)
