How to Fix Azure AD Password Expiration Policy Not Enforced
Question details
The configured 90-day password expiration policy in Microsoft Entra ID (Azure AD) is not being enforced for certain users.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Managing user authentication and security policies in a cloud-only environment.
- Observed behavior
- Some users are able to continue using the same password beyond the 90-day expiration period, ignoring the tenant's global expiration policy.
Ensure you are signed into your tenant with Global Administrator or Privileged Authentication Administrator permissions to access and modify user password policies.
Check User Policies with Microsoft Graph PowerShell
Use Microsoft Graph PowerShell to verify the exact password expiration attributes applied to the affected users.
Individual user properties can sometimes override the global tenant policy. Checking attributes via PowerShell is the most reliable way to identify if a 'DisablePasswordExpiration' flag has been set on specific accounts.
Open PowerShell as an Administrator and run the command 'Install-Module Microsoft.Graph' to install the necessary module.
Run 'Connect-MgGraph -Scopes "User.ReadWrite.All"' and sign in using your Microsoft Entra administrator credentials.
Run 'Get-MgUser -UserId <user-email> -Property PasswordPolicies, LastPasswordChangeDateTime'. Look at the output to see if 'DisablePasswordExpiration' is listed under PasswordPolicies.
If the policy is disabled, run 'Update-MgUser -UserId <user-email> -PasswordPolicies None' to clear the override and enforce the tenant's 90-day expiration.

Verify Global Password Policies in Microsoft 365
Ensure the overall tenant password policy is correctly configured and applied globally.
Open a Microsoft Support Ticket
Escalate the issue to Microsoft Support if PowerShell configurations and global policies are correct but the issue persists.
Ensure Uninterrupted Productivity with WPS Office
While resolving Microsoft Entra ID administration issues, make sure your team's document workflows remain seamless. WPS Office is a highly compatible, free, and lightweight alternative to Microsoft Office, providing powerful tools for documents, spreadsheets, and presentations.
- 1. Visit the official website: Go to the WPS Office website and download the free installer for your operating system.
- 2. Install the software: Run the downloaded executable and follow the simple on-screen instructions to complete the setup.
- 3. Open and edit files: Launch WPS Office to seamlessly open, edit, and save your existing Office documents.

Frequently Asked Questions
Why does a user's password policy show 'DisablePasswordExpiration'?
This attribute can sometimes be unintentionally applied during bulk user creation, PowerShell scripting errors, or during migrations from other directory services. You can clear this attribute using Microsoft Graph PowerShell.
Does password hash synchronization affect cloud expiration policies?
Yes. If your tenant syncs identities from an on-premises Active Directory using Password Hash Synchronization (PHS), the cloud password expiration policy is typically bypassed. In these hybrid setups, expiration must be managed through on-premises AD policies.
How long does it take for password policy changes to apply?
Changes to the global password expiration policy in Microsoft 365 or Microsoft Entra ID can take up to 24 hours to fully propagate and enforce across all user accounts in the tenant.
Can I force a user's password to expire immediately?
Yes. An administrator can go to the Microsoft Entra admin center, select the user, and use the 'Reset password' or 'Require re-register MFA' option, forcing them to establish new credentials upon their next login.




