Why this matters
Length beats complexity. Current NIST guidance favours long passphrases, no forced periodic changes and blocking known-breached passwords, over rules like one symbol and one capital letter.
Humans should get passphrases and MFA. Service accounts and break-glass accounts should get long random secrets kept in a vault, and ideally be replaced by managed identities altogether.