When the PasswordNeverExpires flag is set, a stolen credential stays valid forever. Non-expiring passwords are one of the most common findings we see in Active Directory. Here is how attackers find and abuse these accounts, how to identify them in your environment, and how to close the gap for good.