Alex Weinert
- Published 'Your Pa$$word doesn't matter', reframing password policy around MFA
- Drove Microsoft's published account-compromise telemetry into public guidance
- Led identity security and protection for Microsoft's identity platform
Bio
Alex Weinert leads identity security work at Microsoft and is the author of a run of posts that changed how the industry talks about passwords, most famously "Your Pa$$word doesn't matter," which argued from Microsoft's own attack telemetry that composition rules and rotation policies barely move the outcome while multi-factor authentication does.
Profile built from public employer publications and press records.
Where their work shows up
The argument landed because of the data behind it: Microsoft sees attack traffic at a volume almost nobody else can observe, and publishing what actually compromises accounts made the case that a security team could take to its own leadership. It is a large part of why complexity rules and forced rotation fell out of favour, and why MFA and then phishing-resistant methods became the default recommendation. See password spraying, MFA fatigue, and what is passwordless.
Related on Start with Identity
- GlossaryAuthenticator Assurance Level (AAL)
NIST 800-63B levels describing authentication strength. AAL1: single factor. AAL2: multi-factor. AAL3: multi-factor with phishing-resistant cryptographic authen
- GlossaryCIBA
Client-Initiated Backchannel Authentication. An OpenID Connect flow where authentication is initiated on one device and approved on another, useful for call cen
- GlossaryHOTP
HMAC-based One-Time Password (RFC 4226). A counter-based one-time code and the basis for TOTP. Largely superseded by time-based codes and phishing-resistant met
- CVEOkta Verify for Windows local privilege escalation
Okta Verify on Windows could be turned into a local privilege escalation. The MFA app on the endpoint is part of the identity plane. Pair with Okta's 2024 FastP
- CVEZimbra ZCS chained with CVE-2025-48700 to steal MFA backup codes
Zimbra Collaboration Suite, chained with CVE-2025-48700, was used to steal MFA backup codes and app passwords (CERT-UA UAC-0233). Added to CISA KEV in mid-March
- ExpertChief Identity Architect, Microsoft (former)
Kim Cameron (1948 to 2021) joined Microsoft in 1999 through its acquisition of ZoomIt, the digital identity company he co-founded, became architect of Active Di