User account with old passwords

Old Active Directory passwords expose users to unauthorized access if not regularly updated.
AD domain account’s password set to never expire

Attackers can maintain persistence and reuse compromised credentials when a domain account has a non-expiring password in Active Directory.
Privileged AD account password set to never expire

A privileged AD account with a non-expiring password exposes Active Directory resources to persistent attacker access until the password is changed.