Business Email Password Policy for Small Teams
A password policy for business email should be short enough that people follow it. On MailShrine, aim for unique long passwords, a password manager, and 2FA — not quarterly forced resets that end as Company1! on a sticky note.
Real-life example: Loom & Lattice Studio
Elena (different Elena — design lead) managed four mailboxes for a textile studio: founder, studio, billing, and a seasonal intern. Everyone “remembered” variants of the shop Instagram password. When the intern’s laptop was stolen from a danfo, every inbox was at risk.
They spent one Friday afternoon: password manager seats, 20+ character unique passwords, 2FA on each mailbox, and a written exit checklist for offboarding.
Minimum policy that actually works
| Rule | Requirement | Why |
|---|---|---|
| Length | 16+ characters (passphrase OK) | Beats short complex trivia |
| Uniqueness | Never reuse with banking, Instagram, or WhatsApp | Breach dumps are common |
| Manager | 1Password / Bitwarden / etc. for the team | Shared vault > shared whiteboard |
| 2FA | Required for every human login | Password alone is not enough |
| Sharing | No shared mailbox passwords in Slack/WhatsApp | Use aliases or proper seats |
| Rotation | Change after suspicion or departure | Skip pointless 90-day churn if unique + 2FA |
NIST-style guidance de-emphasizes frequent mandatory changes when passwords are unique and monitored — save resets for incidents and exits.
Step 1: Pick one password manager for the company
Owner pays for seats. Personal managers for personal accounts is fine — business vaults hold business secrets.
Step 2: Rewrite every mailbox password
- Generate a new 16–25 character secret in the vault.
- Change it in MailShrine account security.
- Update desktop/mobile clients (or re-add the account).
- Sign out other sessions if your host exposes that control.
Step 3: Ban the anti-patterns out loud
Put this in a one-page “Email security” note:
- No
Name@Business2026. - No passwords in email drafts.
- No screenshots of passwords in group chats.
- No one master password for
hello@/support@across five people — prefer aliases into one owner mailbox or separate seats.
Step 4: Require 2FA the same day
Password policy without 2FA is half a lock. Follow Secure business email with 2FA.
Step 5: Offboarding within the hour
When someone leaves:
- Reset their mailbox password (or delete/disable the seat).
- Revoke app passwords / OAuth grants if any.
- Check forwarding rules and mailbox filters (incident playbook).
- Remove them from the password vault group.
Checklist
- Team password manager in useCompleted
- Unique 16+ char secrets on all mailboxesCompleted
- 2FA requiredCompleted
- Exit password reset documentedCompleted
- Annual tabletop: “laptop lost — what now?”Not completed
Common mistakes
- Rotating passwords every 30 days and allowing reuse of last year’s pattern.
- One Google Sheet titled “emails.”
- Strong owner password + weak finance mailbox.
- Ignoring DNS spoofing because “we have good passwords” — still publish SPF/DMARC.
Next steps
Citations & References
- Reference: NIST SP 800-63B (passwords & authenticators)
- Reference: NCSC: Password administration for system owners
- Reference: CISA: Secure your accounts
Written by Elena M., SME Security Coach. Elena turns password chaos into a one-page policy teams actually keep.




