Microsoft has removed the 16 character Azure Active Directory password limit and admins can now use up to a maximum of 256 characters. This aligns the passwords lengths with those of on-premises Windows Active Directory services. Last month, Microsoft also stated that they were dropping password-expiration policies from Windows 10 1903 as they felt it was a flawed defense method. Microsoft recommends organization use more modern password-security practices such as multi-factor authentication, banned password lists, brute force detection, and anomalous logon attempt detection.
Source: https://www.bleepingcomputer.com/news/microsoft/azure-active-directory-now-supports-256-character-passwords/

