This topic applies to the following Microsoft Office 365 plans: Microsoft 365 Business Basic, Microsoft 365 Business Standard, Exchange Online, Enterprise E1, and Enterprise E3. 

User passwords expire on a regular basis in Office 365. As a Global Admin, you can make the user's password expire after a certain number of days or set the password to never expire. You can also change the number of days before users are notified of password expiration. By default, passwords are set to expire in 90 days.

  1. Sign in to Office 365 with your work or school account.

  2. Go to the Office 365 admin center.

  3. In the admin center, go to the Settings > Settings.

  4. Go to Security & Privacy page and select Password expiration policy.

    • If you don't want users to have to change passwords, select Passwords never expire. Users won't get any reminders anymore to change their passwords.
    • If you want user passwords to expire:
      1.  Select the checkbox next to Set user passwords to expire after a number of days.
      2. Type the number of days before the password should expire. Choose a number of days from 14 to 730.
      3. Type the number of days before users are notified that their password will expire. Choose a number of days from 1 to 30.
  5. Click Save.

For more information, read the Knowledge Base article on how to set the password expiration policy for your organization.

More about passwords and password expiration policies

  • How can I set the password to never expire for an individual user? Use the Microsoft Online Services Module for Windows PowerShell to set an individual user password to never expire. Check out Set user passwords to never expire.

  • How many days should I choose if I want user passwords to expire? Many organizations require new passwords every two or three months. Choose a number of days from 14 to 730.

  • How are users notified that their password will expire? Users see a message whenever they sign in, starting at the number of days before password expiration that you specified. The message shows the number of days left before the password expires and gives a link to the Change password page. For more information, see Change your password.

  • What if users don’t change their password in time? Users can still change their password after it has expired. The Update password page displays when they sign in, and they can enter a new password. You can also reset their password for them, if necessary. For more information, see Change your password or Reset user passwords.

  • What if I want to change password policy for accounts that are synchronized with Active Directory? Password policy can only be set using the steps in this article for accounts that aren’t synchronized through Active Directory synchronization. To learn more about Active Directory synchronization, check out Office 365 integration with on-premises environments.