Today, a strong password alone is no longer sufficient. Where possible, use a passkey, always activate multi-factor authentication (MFA), and use a unique password for each account. FLEXAMIT is happy to assist you in setting these up correctly.
Use a passkey where possible. If that is not yet possible, protect your account at least with MFA and a long, unique password. Store passwords in a reliable password manager.
1. Passkeys: the best choice where possible
A passkey replaces the traditional password with a more secure way of logging in. For example, you log in using Windows Hello, a fingerprint, facial recognition, or the secure unlocking of your smartphone.
A passkey is linked to the specific website or application for which it was created. Therefore, the same passkey cannot be used on another website.
Why are passkeys safer?
- You don’t have to remember or type a password.
- A passkey is unique for each website or application.
- Passkeys are designed to withstand phishing attacks.
- An attacker cannot easily steal your passkey via a fake login page.
- The secret key never leaves your device.
2. Always use multi-factor authentication
When an account still uses a password, a password alone is insufficient protection. Therefore, always activate multi-factor authentication (MFA) when available.
With MFA, you must prove your identity in a second way besides your password. This can be, for example:
- an authenticator app;
- Windows Hello;
- a security key;
- a passkey;
- another authentication method approved by your organisation.
3. Never use the same password twice
Each account must have its own, unique password.
So never use the same password for, for example, your Microsoft 365 account, LinkedIn, Facebook, an online shop, and your personal email.
Suppose you use the same password for an online shop and your business Microsoft 365 account. If that online shop is hacked and your password leaks, criminals can automatically try that same email address and password on Microsoft 365 and other popular services.
Thus, a data breach at a completely different organisation can eventually lead to access to your business account.
4. Use a password manager
Because each account must have a unique password, it is not realistic to remember dozens of complex passwords yourself.
Therefore, FLEXAMIT recommends using a password manager.
A good password manager can:
- generate a long and unique password for each website;
- store your passwords securely and encrypted;
- auto-fill passwords;
- prevent you from using the same password everywhere;
- help you identify suspicious or leaked passwords more quickly.
Protect your password manager with a very strong master passphrase and also activate MFA or a passkey there. After all, your password manager contains access to many of your other accounts.
5. Still need a password? Prioritise length
Not every application supports passkeys yet. When you have to choose a password yourself, length is more important than artificial complexity.
Preferably use a long password or passphrase of at least 15 characters. Longer is better.
A good password:
- is at least 15 characters long;
- is unique to that one account;
- does not contain a name, company name, username, or easily guessed personal information;
- does not appear in lists of commonly used or leaked passwords;
- is preferably automatically generated by your password manager.
6. Creating a passphrase
When you have to remember a password yourself, a passphrase can be easier and safer than a short, complicated password.
Choose several random words that together form a long combination.
Canoe-Cloud-Coffee-Planet-72This example is only intended to illustrate the principle. Do not use this example as a real password.
A good passphrase:
- consists of multiple words;
- is long;
- is relatively easy for you to remember;
- is not based on a well-known quote, song lyric, or proverb;
- does not contain predictable personal data such as names or birthdates.
a with @, o with 0, and adding ! at the end. Such patterns are predictable and provide much less extra security than a longer passphrase.
7. What should you never do?
- Never use the same password for different accounts.
- Never share your password via email, Teams, WhatsApp, or other messaging.
- Do not store passwords in an unsecured Word, Excel, or text file.
- Do not write passwords on a post-it note next to your computer.
- Never approve unexpected MFA requests.
- Never give your password to someone who asks for it by phone or email.
- Do not use simple variants such as
Welcome2026!,CompanyName123, orSummer2026!.
8. Do you think your password has been leaked?
Do you think someone knows your password, have you entered it on a suspicious website, or have you received an unexpected MFA request?
Do not wait until you actually notice that someone has taken over your account.
The FLEXAMIT approach
For good user account security, we recommend, in this order:
- Use a passkey when the application supports it.
- Activate MFA on accounts still using a password.
- Use a unique password for each account.
- Use a password manager to securely generate and store passwords.
- If you must remember a password yourself, choose a long passphrase.
FLEXAMIT can help you implement MFA, passkeys, and password management within your organisation. For this, contact your FLEXAMIT representative or our service desk.
Comments
0 comments
Please sign in to leave a comment.