Creating and Managing Strong Passwords
Security / Antivirus
password
security
strong password
password manager
By Kerry · Updated 03/04/26 10:41 PM
Weak passwords are one of the leading causes of business account compromises. Here's what you need to know.
What makes a strong password:
- At least 12 characters (longer is better)
- Mix of uppercase, lowercase, numbers, and symbols
- Not a real word or name
- Not related to you (no birthdays, pet names, company names)
- Unique — never reused across different accounts
Examples:
Weak: Summer2024!, Password1, CompanyName123
Strong: xT7#mP2qLw!9vN, kite-horse-blue-42
The problem with trying to remember strong passwords:
Most people can't memorize a unique strong password for every account, so they reuse the same one. If that one password gets stolen from any site, every account using it is compromised.
The solution: Use a password manager
A password manager stores all your passwords in an encrypted vault, locked with one master password. It:
- Generates strong unique passwords automatically
- Fills them in for you so you don't need to remember them
- Syncs across all your devices
- Alerts you if a saved password appears in a known data breach
Recommended password managers for businesses:
- Bitwarden — free for individuals, affordable for teams
- 1Password — excellent for business teams with shared vaults
- LastPass Business — widely used in corporate settings
Password best practices:
1. Use a password manager — this is the #1 recommendation
2. Enable MFA (multi-factor authentication) on all critical accounts (Microsoft 365, email, banking)
3. Never share passwords via email or text message — use a secure sharing feature in your password manager
4. Never use the same password on multiple sites
5. Change passwords immediately if you suspect a breach
Never share your Microsoft 365 password with anyone — including IT support. We never need your password to help you.