The 2026 AD password policy in one chain:
1. MFA universal
2. Banned-password list active
3. Length up (14 w/ MFA, 15 single-factor)
4. Complexity OFF (only after 1-3)
5. Expiration OFF (only after 1-3)
6. Service accounts to gMSA
Skip a step, weaken the domain. Full playbook 👇