| Without MFA | With MFA | Administration Account | Microsoft 365 | |
| Multi-factor Authentication | — | Required | Required | Enforce registration for multi-factor authentication and enable risk-based multi-factor authentication challenges |
| Min Password Length | 6 or more | 12 or more | 16 or more | 12 or more |
| Password Complexity | Required | Required | Required | Required |
| Max Password Age | 90 days | 180 days | 180 days | 180 days |
| Min Password Age | 5 days | 5 days | 5 days | 5 days |
| Password History | 10 passwords | 10 passwords | 10 passwords | 10 passwords |
| Lockout | 3 attempts | 5 attempts | 5 attempts | 5 attempts |
| Lockout Duration | 0 minutes (require admin to unlock) | 30 minutes | 30 minutes | 30 minutes |
| Use of Password Policy Tool / Filter / Password Dictionary (e.g., nFront) | Recommend | Recommend | Recommend | Recommend |