Azure AD SSO Password Rotation Not Enforced in my Active Directory Domain

Seema Kanwal Gurmani 336 Reputation points
2025-07-29T04:29:38.8533333+00:00

Dear Community

Kindly note that we have a single domain and single tree. We have four sites and each site has its own domain controller. They are all getting synced. I have local active directory getting synced with Azure AD for office 365 accounts. Now we had VAPT done by a third party and they have said that the "Azure AD SSO Password Rotation is Not Enforced". I wanted to know What is the recommended standard practice? and If its recommended to change what will be its impact in my environment as explained previously?

I have selected tage as ADFS but I have active directory domain services.

Thanks.

Microsoft Security | Active Directory Federation Services
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.