It's a pain for users, but it is a good idea to require all users to update their password periodically (every 6 to 12 months). Starting in xTuple version 4.10, administrators can set the system to require password updates. Go to
to turn this feature on/off and set the required reset days.