If you access corporate email on a personal device that can be unlocked with FaceID, you must change your face at least once every sixty days.

You may not reuse any of your most recent 12 faces.

#infosec #PasswordExpiration #BYOD

@maxleibman our policy is to change faces every 30d, unless there's indication your face has been compromised. In that case an immediate face change is required to access company assets.
@jackscerebellum @maxleibman We also enforce Strong Faces that can't be easily identified by others.
@mykl @jackscerebellum @maxleibman Are you saying long faces are better for security?
@Obdurodon @mykl @jackscerebellum Infosec policy definitely gives me a long face!