FREE TEMPLATE
Password and Authentication Policy
MFA everywhere, a password manager, and why a forced reset every 90 days is no longer the right answer.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change
Purpose
Stolen and reused credentials are the most common way small businesses get breached. This policy sets the rules for how accounts at [COMPANY NAME] are protected.
Scope
Applies to every account used for company business — email, file storage, finance and payroll systems, the CRM, remote access, vendor portals, social media, domain and DNS accounts, and any administrative account on a company device or system.
Applies to every employee, contractor and vendor who holds such an account.
Multi-factor authentication
Multi-factor authentication (MFA) is required on every account that supports it. No exceptions for executives.
Approved methods, in order of preference:
- A hardware security key (FIDO2 / passkey)
- An authenticator app with number matching
- A push notification from an approved authenticator
SMS text codes are permitted only where a system supports nothing better, and those systems should be identified and replaced over time. Text messages can be intercepted by porting your phone number.
Never approve an MFA prompt you did not personally trigger. If prompts arrive that you did not request, your password is already compromised — report it immediately and change it.
Passwordless sign-in
Where a system supports it, [COMPANY NAME] prefers passwordless sign-in — Windows Hello for Business, platform passkeys, or a hardware security key. These are phishing-resistant in a way that no password is.
This does not retire the rest of this policy. The account behind a passwordless sign-in usually still has a password, and that password remains a valid way in for anyone who finds it. Plenty of systems support nothing else: line-of-business applications, vendor portals, service accounts, network equipment, the copier. Passwordless raises the floor for daily sign-in; it does not remove the credential underneath.
Passwords
Where passwords are still used:
- Minimum 16 characters. Length beats complexity; a passphrase of four unrelated words is stronger and easier to remember than a short string of symbols.
- Every account gets a unique password. Reuse is what turns one breach at an unrelated company into a breach at yours.
- Passwords are not rotated on a schedule. Forced expiration produces predictable patterns —
Summer2026!becomesFall2026!— and weaker passwords overall. This follows current NIST guidance. Passwords are changed when there is a reason to: a suspected compromise, a departure, or a vendor breach notice. - Passwords are screened against known-breached password lists where the system supports it, and rejected if they appear. This is what replaces scheduled rotation: you are checking whether a password is actually exposed rather than assuming it went stale on a calendar.
- Never share a password by email, text or chat. Never write one on paper left at a desk.
- Never reuse a company password on a personal account, or a personal password on a company account.
Password manager
[COMPANY NAME] provides a password manager, and it is the only approved place to store company credentials. Browser-saved passwords, spreadsheets, notes apps and shared documents are not approved.
Shared credentials for systems that do not support individual logins must live in a shared vault with access limited to the people who need it — never circulated by message.
Administrative accounts
Administrative and privileged accounts are held separately from everyday user accounts. Nobody performs daily work — email, browsing, documents — while signed in with administrative rights.
Administrative accounts require MFA, are reviewed at least quarterly, and are removed the same day a person no longer needs them.
The number of people with administrative access to email, finance and the domain registrar should be the smallest number that still lets the business function when someone is on vacation.
Service and shared accounts
Accounts not tied to a person — scan-to-email, a shared info@ mailbox, an automation account — must have a documented owner, a credential stored in the password manager, and the narrowest permissions that let them do their job. They are included in the quarterly access review.
Default credentials
No device or system goes into service with its factory password. This includes firewalls, wireless access points, printers and multifunction copiers, cameras, network storage and anything else with an admin page.
Compromise
If you believe a password has been exposed — you entered it on a suspicious page, you received unexpected MFA prompts, a vendor notified you of a breach — report it to [POLICY OWNER OR IT PROVIDER] immediately and change it. There is no penalty for reporting a mistake quickly. There is significant cost to reporting it late.
Onboarding and departure
Accounts are created only after a documented request from a manager, and only with the access that role requires.
On departure, all access is revoked on the final day. See the Access Control Policy for the full procedure.
Exceptions
Exceptions must be requested in writing from [POLICY OWNER] and documented with a business reason, a compensating control and an expiration date.
Enforcement
Violations may result in loss of access and disciplinary action up to and including termination.
Review
Reviewed at least annually by [POLICY OWNER], and after any suspected credential compromise.
Acknowledgment
I have read and understood the [COMPANY NAME] Password and Authentication Policy, and I agree to follow it.
Name: ______________________________
Signature: __________________________
Date: ______________________________
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your state’s employment law. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
