A work or school administrator can configure password expiration, but Microsoft says its Microsoft 365 admin center and productivity apps no longer provide expiration notifications. A warning may be organization-generated or fraudulent; verify through your known account portal or IT contact.
01
What you may be seeing
Cloud-only Microsoft 365 organizations can configure passwords to expire, although Microsoft recommends that cloud-only passwords not expire by default.
Microsoft’s current administrator documentation says Microsoft 365 apps no longer support password-expiration notifications. An organization can still send its own reminders or use a hybrid identity system.
02
Signals to inspect—and why they matter
Strong evidence
The warning links to a non-organization or non-Microsoft sign-in domain
A password-reset page must belong to the identity system your organization actually uses. A lookalike domain is strong evidence not to enter credentials.
Your known account portal or IT team says no expiration applies
The tenant’s actual policy and official support channel are more reliable than an unsolicited message.
Contextual signals
The email says Microsoft itself will delete mail immediately
Threats and short deadlines are common pressure tactics, but wording alone is not enough. Verify the policy and destination.
Contextual signals can justify caution, but they do not authenticate or condemn a message by themselves.
03
Safe verification steps
Open your normal Microsoft 365 or organization sign-in page yourself; do not use the warning’s link.
Check whether the portal prompts for a password change after you sign in through that known route.
Ask IT or the service desk using contact information from your organization’s directory, not the message.
04
What to do next
Report a fraudulent warning through your organization’s security process and the email client’s reporting control.
If you entered credentials on the linked page, change the password through the official portal and notify IT promptly.