- Product
Kindling
Product Overview
Sophisticated security with unmatched simplicityCloud SIEM
Pre-configured detections across your environmentHoneypots
Deception technology to detect lateral movementEndpoint Visibility
Real-time monitoring with added detection & responseSecurity Reports
Data visualizations, compliance reports, and executive summariesAutomated Response
Detect, prioritize, and neutralize threats around the clockIntegrations
Cloud, on-prem, and open API connectionsXDR Platform
A complete view to identify risk, and things operational
- Pricing
- Why Blumira
Why Blumira
The Security Operations platform IT teams loveWatch A Demo
See Blumira in action and how it builds operational resilienceUse Cases
A unified security solution for every challengePricing
Unlimited data and predictable pricing structureCompany
Our human-centered approach to cybersecurityCompare Blumira
Find out how Blumira stacks up to similar security toolsIntegrations
Cloud, on-prem, and open API connectionsCustomer Stories
Learn how others like you found success with Blumira
- Solutions
- Partners
- Resources
The short version: Blumira no longer forces you to change your password every 90 days. Modern protections like passkeys, breached-password detection, and enforced multi-factor authentication (MFA) protect your account far better than routine password resets ever could. This change follows current NIST guidance, keeps you aligned with PCI DSS 4.0, and makes accounts more secure, not less.
What changed
We have removed the 90-day password expiration and forced-rotation requirement from the Blumira app. You will no longer be prompted to reset your password on a fixed schedule. You can still change your password at any time, and we will still require a change if we ever detect that your credentials may be compromised.
Why we made this change
Scheduled password rotation was designed for a time before strong multi-factor authentication and real-time breach monitoring existed. Today, Blumira protects your account with layered, modern controls that address the ways accounts actually get compromised. A calendar-based password reset could never do that.
Passkeys and advanced authentication
Blumira supports passkeys, a phishing-resistant sign-in method built on the FIDO2/WebAuthn standard. A passkey replaces a typed password with a cryptographic key that stays on your device and is unlocked by your fingerprint, face, or device PIN. There is no shared secret to steal, phish, or reuse, which removes the single biggest reason forced rotation ever existed.
Breached-password detection
When you set or change your password, Blumira checks it against large databases of known-breached and commonly used credentials. If the password appears in a known breach or on a common-password list, we will not let you use it. This targets the real risk, a password that is actually exposed, instead of assuming every password becomes dangerous simply because 90 days have passed.
Enforced multi-factor authentication (MFA)
Blumira enforces strong MFA on accounts, so a password by itself is never enough to sign in. Even if a password were stolen, an attacker still could not reach your account without your second factor. As explained below, this is also what keeps the change compliant.
How your account is protected now
|
Risk |
What forced 90-day rotation did |
What Blumira does now |
|---|---|---|
|
Stolen or phished password |
Little, since the password stayed valid for up to 90 days |
MFA and passkeys make a password alone useless to an attacker |
|
Password exposed in a data breach |
Nothing. You only changed it on schedule |
Breached-password detection blocks or flags it right away |
|
Weak or reused password |
Nothing, and often made it worse (see below) |
Blocked at creation by breached/common-password screening, with passphrase guidance |
Does this affect PCI compliance?
No. Under PCI DSS 4.0 (v4.0.1), the 90-day password-change rule in Requirement 8.3.9 applies only to accounts where a password is the single authentication factor. For those accounts, the standard gives two options: change the password every 90 days, or dynamically analyze the account's security posture and control access in real time.
Because Blumira enforces MFA, a password is no longer the only factor protecting your account, so the 90-day requirement in 8.3.9 does not apply. Combined with breached-password monitoring, you stay aligned with PCI DSS 4.0 without routine rotation.
Why frequent rotation actually weakens security
Security researchers have shown for years that forcing frequent password changes tends to reduce security rather than improve it. When people are made to change passwords on a schedule, they tend to pick weaker starting passwords and then modify them in small, predictable ways.
The U.S. Federal Trade Commission put it plainly: users required to change passwords frequently “select weaker passwords to begin with, and then change them in predictable ways that attackers can guess easily.” A widely cited University of North Carolina study found that once an attacker knew one of a user's previous passwords, they could guess the next one within a handful of tries about 17% of the time, because people rotate in patterns like Spring2025 → Summer2025, or Pumpkin1! → Pumpkin2! → Pumpkin3!.
This is why NIST's current digital identity guidance (SP 800-63B) directs organizations not to require periodic password changes, and to force a reset only when there is evidence that a password has been compromised.
What we recommend instead: use a passphrase
The most effective thing you can do for a password today is make it long. Length beats complexity. A passphrase, several random words strung together, is both far harder to crack and far easier to remember than a short, symbol-heavy password.
- Use four or more random words, for example correct-battery-harbor-melon. NIST favors length and supports passwords up to at least 64 characters, including spaces.
- Aim for at least 15 characters. The longer the passphrase, the stronger it is.
- Make it unique to Blumira. Never reuse a password from another site.
- Use a password manager to generate and store long, unique passwords so you do not have to memorize them.
- Enroll a passkey if your device supports it. It is the strongest and simplest option.
- Keep MFA enabled. It is your single most important protection against account takeover.
What you need to do
Nothing is required. Your current password will keep working, and you will not be prompted to reset it on a schedule. When you are ready, we encourage you to switch to a long passphrase or enroll a passkey, and to keep MFA enabled. If we ever detect that a credential may be compromised, we will prompt you to change it.
References
Tag(s):
Product Updates
Mike Toole
Mike Toole, Head of Security and IT at Blumira, has over a decade of experience in IT. Prior to joining Blumira, he managed IT for Duo Security and Censys. He has broad experience with a range of IT and security focus areas, including compliance, network design, log monitoring, project management, and cross-platform...
More from the blog
View All Posts
Featured
4 min read
| July 27, 2026
If I Could Only Use AI for Three Things in Security
Read More
Life at Blumira
12 min read
| April 13, 2021
What to Expect As a Blumira Engineering Candidate
Read More
Security Trends and Info
6 min read
| May 28, 2025
5 Steps to Minimize Impact After Vendor Security Incidents
Read MoreSubscribe to email updates
Stay up-to-date on what's happening at this blog and get additional content about the benefits of subscribing.