Skip to content

Best Practices for Troubleshooting a Windows Server Upgrade

Best Practices for Troubleshooting a Windows Server Upgrade

To upgrade, or not to upgrade. While that may not have been the question that Hamlet asked, it’s one you might be asking. You already made the mistake of asking Reddit, “should I do an in-place upgrade,” and, as expected, people had Big Opinions. A Windows Server Feature Update offers benefits, like performance and analytics. On the other hand, if you have problems, then your attempts can lead to business downtime and service disruption. Meanwhile, time rolls on toward the October 2025 end-of-service (EoS) for Windows Server 2016.

 

If you’re still trying to decide if or when to do a Feature Update, then these best practices for troubleshooting a Windows Server upgrade might help you.

 

What is an in-place Windows Server upgrade?

An in-place Windows server upgrade, also called a Feature Update, is when an organization updates an older operating system version to a new one without making changes to:

  • Settings
  • Server roles
  • Data

 

By not requiring the IT department to reinstall Windows, the in-place upgrade reduces downtime and business disruption while improving security and system performance.

 

The process for an in-place Windows server upgrade is:

  • Collecting diagnostic information for troubleshooting issues
  • Backing up the server operating system applications, and virtual machines
  • Performing the Feature Update using the Windows Server Setup
  • Checking the in-place upgrade to see if it worked

 

Which version of Windows Server should I upgrade to?

 

Depending on your current operating system, you may have different supported paths:

  • Windows Server 2012: Windows Server 2012 R2, Windows Server 2016
  • Windows Server 2012 R2: Windows Server 2016, Windows Server 2019, Windows Server 2025
  • Windows Server 2016: Windows Server 2019, Windows Server 2022, Windows Server 2025
  • Windows Server 2019: Windows Server 2022, Windows Server 2025
  • Windows Server 2022: Windows Server 2025
  • Windows Server 2025: Windows Server 2025

 

Microsoft no longer supports Windows Server 2008 or Windows Server 2008 R2.

Reasons for Upgrading Windows Servers

Upgrading Windows Server provides many of the same benefits that updating other device operating systems (OS) provides.

1. Enhanced Security

As with any operating system, the Windows Server upgrades typically incorporate new security features. For example, Windows Server 2022 brought with it:

  • Secured-core server: hardware, firmware, and driver capabilities to mitigate security risks during boot, at the firmware level, and from OS executing unverified code
  • Secure connectivity: implementing HTTPS and TLS 1.3 by default, encryption across DNS and Server Message Block (SMB),

 

Meanwhile, Windows Server 2025 includes security upgrades for:

  • Name and Sid lookup forwarding between machine accounts
  • Confidential attributes
  • Default machine account passwords
  • LDAP encryption by default

 

2. Improved Performance

The OS updates improve performance by changing how processes work. For example, Windows Server 2022 improved performance with changes like:

  • Encrypting SMB data before data placement
  • Reducing Windows Container image sizes
  • Improving both UDP and TCP networking performance
  • Enhancing Hyper-V virtual switches with Receive Segment Coalescing (RSC)
  • Allowing users to adjust storage repair speed
  • Making storage bus cache available for standalone servers

 

Meanwhile, Windows Server 2025 improves performance with changes like:

  • Block cloning support
  • Dev Drive storage volume focused on file system optimizations that improve control over storage volume settings
  • Enhanced Log to reduce impact on Storage Replica log implementation

 

3. Enhanced Efficiency and Agility

As the world migrates to hybrid on-premises and cloud infrastructures, the upgrades to Windows Server follow along. For example, Windows Server 2022 came with new Azure hybrid capabilities with Azure Arc, a way to manage Windows and Linux physical servers and virtual machines hosted outside of Azure to maintain consistency. With Windows Server 2025, the Azure Arc setup Feature-on-Demand is installed by default so adding servers is easier.

 

Challenges with Windows Server Upgrades

While upgrading Windows Server comes with multiple benefits, you may be concerned about the potential problems and challenges, including:

  • Compatibility issues: Applications running on the server may not work with the new OS version, leading to outages.
  • Configuration restrictions: Server boot configurations may complicate the upgrade process, requiring reconfiguration or virtualization changes.
  • Disk space: Upgrades typically require extra space for installation files and temporary processing or else they fail.

 

How to Troubleshoot a Windows Server Upgrade

While you want everything to work perfectly, you don’t live in a perfect world. If you have to troubleshoot your Windows Server upgrade, then you might want to consider some of these issues.

Review event logs

Using the Event Viewer, you can scan the System and Application logs for Windows Events generated around the same time you did the upgrade. Some Windows Server error codes include:

  • 0x80244007: Windows cannot renew the cookies for the Windows Update
  • 0x80072EE2: WIndows Update Agent unable to connect to the update servers or your update source, like Windows Server Update Services (WSUS)
  • 0x8024401B: Proxy error leads to Windows Update Agent being unable to connect to update servers or your update source, like WSUS.
  • 0x800f0922: Updates for Windows Server 2016 failed to install.
  • 0x800706be: Windows Server 2016 cumulative update failed to install and was
  • 0x80090322: HTTP service principal name (SPN) registered to another service account so PowerShell unable to connect to a remote server using Windows Remote Management (WinRM)

 

Check for Pending Reboot

An upgrade typically requires four reboots. After the first reboot, you can expect another within 30 minutes. If you see no progress, the upgrade may have failed.

 

Review Servicing Stack Updates

The servicing stack updates (SSUs) fix problems with the component that installs the Windows Server updates to make sure they’re reliable. Without the latest SSU installed, you may not be able to install the feature or security updates.

 

Check CPU and I/O

Since the Windows Server upgrade uses a lot of compute power and disk space, you want to make sure that you check these metrics to make sure the process is progressing.

 

Check Firewall Service

You may need to have the Windows firewall service running for the updates to work. To check whether the service is running, go to Service Manager>Services>Windows Firewall.

 

Graylog Enterprise: Faster Troubleshooting

Graylog Enterprise enables you to aggregate, correlate, and analyze all your log data in a single location. With Graylog Extended Log Format (GELF) inputs and BEATS inputs, you have a standardized format across Windows log types

Graylog supports Winlogbeat to ingest Windows event logs directly into our BEATS input, or you can use the NXLog community edition that reads Windows event logs and forwards them in GELF.

Using Graylog Sidecar, you can implement multiple configurations per collector and centrally manage their configurations through the Graylog interface. Graylog Cloud accepts inputs from the Graylog Forwarder so that you can collect the same kind of logs from different parts of your infrastructure or maintain a more redundant setup.

About Graylog  
At Graylog, our vision is a secure digital world where organizations of all sizes can effectively guard against cyber threats. We’re committed to turning this vision into reality by providing Threat Detection & Response that sets the standard for excellence. Our cloud-native architecture delivers SIEM, API Security, and Enterprise Log Management solutions that are not just efficient and effective—whether hosted by us, on-premises, or in your cloud—but also deliver a fantastic Analyst Experience at the lowest total cost of ownership. We aim to equip security analysts with the best tools for the job, empowering every organization to stand resilient in the ever-evolving cybersecurity landscape.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How to choose the best DNS filtering solution for your business

Summary: Discover key factors for selecting a DNS filtering solution that enhances network security, boosts productivity, and ensures compliance for your business.

Now, businesses face many online threats that can jeopardize network security, reduce employee productivity, and compromise regulatory compliance. Domain Name System (DNS) filtering is a powerful tool for protecting against these threats by blocking access to harmful websites—those that may host malware, phishing attempts, or inappropriate content.

Beyond protecting your network, DNS filtering tools improve workplace productivity by limiting access to non-work-related websites. They also help ensure compliance by restricting access to certain types of content.

However, with many DNS filtering providers available, selecting the right one can be overwhelming. This guide will walk you through the key factors to consider when choosing the best DNS filtering solution for your organization.

How DNS filtering solutions work

DNS filtering is like a gatekeeper for internet usage, preventing access to malicious or inappropriate websites before they can harm your network. By intercepting DNS queries—requests users make when accessing a website—the filtering system determines whether the requested domain is safe based on predefined security policies.

Typically, DNS servers function like an internet “phonebook,” translating domain names into IP addresses to connect your browser and the required website.

With a DNS filtering solution in place, however, each query undergoes additional checks. If the requested site is flagged on a blocklist or is identified as a security risk, the DNS resolver blocks the request, preventing the page from loading and neutralizing potential cyber threats.

Benefits of implementing a DNS filtering solution

Deploying a DNS filtering solution offers a range of benefits that go beyond basic Internet browsing controls:

Internet threat prevention

Each organization should control employee online traffic. By blocking access to sketchy sites full of malware, phishing, or ransomware, DNS filtering solutions shield your network from all kinds of cyber-attacks before they even have a chance to strike.

Keeping productivity on point

Let’s face it—distractions are everywhere. DNS filtering tools help minimize those distractions by blocking non-work-related sites so your team can stay focused and get more done.

Improved network performance

No more bandwidth hogs. A DNS filtering solution ensures your network runs smoothly and efficiently by limiting heavy streaming or large file downloads.

Security compliance

Worried about regulations? DNS filtering helps you meet industry standards by controlling access to restricted content and protecting your business from potential legal and reputational risks.

Keeping remote workers safe

With more people working remotely, DNS filtering solutions block online threats and secure sensitive data, no matter where your employees log in.

Filtering for safer Internet access

Whether it’s a school, home, or workplace, DNS filtering blocks inappropriate or harmful content, creating web filtering for schools or employees.

 

5 considerations for choosing the best DNS filtering solution

When it comes to selecting a DNS filtering provider, it’s essential to weigh your options carefully. With so many choices out there, understanding the key factors can help you find the right fit for your organization. Here are some critical considerations to keep in mind:

#1 Technical architecture

The backbone of a solid DNS filtering solution is its technical architecture. You’ve got two main options: cloud-based or on-premise. Cloud-based solutions are super scalable. They make it easier to grow with your business’s security needs. They are also easier to deploy, need less maintenance, and usually come with real-time updates.

On-premise solutions give you more control over your data. This can be a big help if you have strict privacy rules. However, they might require higher initial costs, more time, and greater expertise to maintain.

Another thing to keep in mind is DNS resolution speed—how fast it can process requests and load websites. A provider with a global network will keep things running smoothly with less lag when accessing sites.

#2 Advanced threat detection

In today’s world, you need more than just the basics. Look for a DNS filtering solution that’s equipped with advanced threat detection. Such a solution must monitor network activity in real-time, spotting and blocking threats like malware and phishing before they can mess with your network. As cyber threats keep evolving, having a tool that adapts is a must.

#3 Integration with existing systems

Whatever DNS filtering solution you pick should be compatible with your current system. Make sure it works well with your existing security infrastructure, like your firewall or Security Information and Event Management (SIEM) tools. Some providers even offer API access for easy integration with third-party tools or custom solutions. A smooth integration means less hassle for your IT team and a more seamless security experience.

#4 Granular policy management

DNS filtering is designed to restrict access to specific content, but when it comes to defining exclusive rules for network access, we enter a different technological area. Therefore, when selecting DNS filtering solutions, it’s best to look for comprehensive products beyond content restriction and address network access use cases.

Fine-tuning access with your DND filtering solution helps boost productivity and security, keeping everyone where they need to be.

#5 Real-time analytics and reporting

Keeping tabs on what’s happening in your network is essential. Make sure your DNS filtering provider offers real-time analytics and reporting so you can spot potential threats, check network activity, and stay compliant. Detailed DNS query logs and custom reports are especially useful for digging into incidents or proving you’re following industry regulations.

Tips for selecting the best DNS filtering solution

  • Check out content control features: Look for customizable filtering options that let you block malware, phishing attempts, adult content, gambling sites, and more. Keeping distractions and risks at bay is key for productivity and compliance.
  • Make sure it has solid security features: Don’t settle for basic protection. Your DNS filtering solution has strong encryption, advanced threat detection, and malware protection. These features add extra layers of security, especially when your data is in transit.
  • Go for user-friendly setup and centralized management: Setting up DNS filtering shouldn’t be a headache. Look for something simple to install with centralized management so your IT team can control everything from one spot, enforce policies, and quickly handle any issues.
  • Look for customization options: Every business is different, so you’ll want a solution that lets you fine-tune filtering rules to fit your specific needs. Flexibility is key to keeping security tight without slowing down business activities.

Conclusion

Choosing a DNS filtering solution for your business is critical. It impacts everything from your cybersecurity to productivity and compliance. Take the time to evaluate things like the technical architecture, how the provider handles threats, and how well the solution integrates with your current systems. Opt for providers that offer robust security, real-time reporting, and detailed control over access to make sure you’re getting the best DNS filtering solution possible.

With the right DNS filtering in place, you can protect your network, control online interactions, and create a safer, more productive work environment for your team.

How NordLayer can help

NordLayer offers easy-to-use DNS filtering capabilities to protect your network. With features like DNS filtering by category, Web Protection, and Download Protection, keeping your team safe is simple. Setup is quick, even for non-tech users, and managing security for your whole team is straightforward.

  • DNS filtering by category allows IT admins to block content from over 50 categories. This helps keep your network secure and your team focused.
  • Web Protection automatically blocks access to websites that are flagged as potentially malicious.
  • Download Protection scans every new file download and removes harmful files before they can infect your devices.

These features can work together to prevent risks like malware infections and phishing. But that’s not all. All NordLayer customers get encrypted connections and masked IP addresses. This ensures your internet access is secure, no matter where you are.

Want to learn more? Contact NordLayer’s sales team to see how we can help protect your network.

 

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Penta Security Launches a Cloud Security Provider WAF Managed Service on AWS Marketplace

 

Penta Security, a leading cyber security company and provider of web application security in the Asia-Pacific region, announced that Penta Security’s Cloudbric WMS has officially launched a usage-based SaaS subscription model on AWS Marketplace in December of 2024.

Cloudbric WMS (WAF Managed Service) is a managed service developed for Cloud Service Provider Web Application Firewalls (CSP WAF), such as AWS WAF.

While CSP WAFs are powerful security tools, as CSP WAFs typically require the users to configure the security rules themselves, it can be quite difficult to utilize the CSP WAFs to their full potential.

To address this issue, Penta Security has developed a managed service that optimizes the security rules and provides a dedicated console to monitor the security status for AWS WAF users. When Cloudbric WMS is adopted, the security experts of Penta Security initially analyze the user’s logs and optimize the rules for maximum efficiency fit to the unique environment of the user.

Once the initial security rule optimization process is completed, the user will be provided access to a dedicated console for monitoring and security rule configurations. Through Cloudbric WMS, the user can gain better insight and control of the security rules for their AWS WAF.

The security rules utilized by Cloudbric WMS is based on the security technologies and expertise of Penta Security’s own WAF, WAPPLES, which has protected the web services for enterprises since 2005 and has recently been validated by a third-party testing firm to have a top-tier detection rate. These security rules are also provided in AWS Marketplace in the form of managed rule groups, which are presets of security rules provided by Independent Software Vendors for AWS WAF.

Taejoon Jung, director of the Planning Division at Penta Security stated, “Cybersecurity is always a difficult subject and an area that requires a certain level of expertise. However, it is our vision to provide an easier solution for security. We expect Cloudbric WMS will boost their AWS WAF experiences simply by subscribing to the service.”

Cloudbric WMS for AWS WAF (PAYG) product is available for subscription in the AWS Marketplace. AWS Marketplace is a curated digital store where users can search, evaluate, purchase, distribute and manage solutions provided by AWS Partners.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Leveling Up Security Operations with Risk-Based Alerting

In life, you get a lot of different alerts. Your bank may send emails or texts about normal account activities, like privacy notices, product updates, or account statements. It also sends alerts when someone fraudulently makes a purchase with your credit card. You can ignore most of the normal messages, but you need to pay attention to the fraud alerts. Security is the same way. Since your systems can generate terabytes of data everyday, your security tools can fire high volumes of alerts, leaving you overwhelmed. 

With risk-based alerts, you can reduce alert fatigue by incorporating additional security information, giving you a way to focus on high-value issues.

What is risk-based monitoring in cybersecurity?

In cybersecurity, a risk-based approach to monitoring means that the organization assesses the business impact and likelihood of an attack against various:

  • People
  • Devices
  • Resources
  • Networks
  • Data

 

After identifying those people and assets who pose the highest risk, the security team often incorporates threat intelligence to help prioritize monitoring and remediation activities. For example, many security teams take a risk-based approach to vulnerability management by appling security updates to critical assets first. 

What is risk-based alerting?

Risk-based alerting (RBA) means that the detection logic incorporates additional attributes to reduce the overall number of alerts generated while enhancing them with meaningful data. 

When security analysts write these alerts, they may include security metadata including:

  • Exploitability, like an asset’s distance from the public internet
  • Impact, like users with privileged access
  • Likelihood, like incorporating threat intelligence
  • Asset criticality, like databases storing personally identifiable information (PII)

 

With RBA, security analysts can align their monitoring activities to the organization’s risk assessment more effectively. Further, when security teams have a solution that enables threat hunting, they can proactively use these enhanced rules to detect suspicious activity in their systems. 

What are the benefits of risk-based alerting?

While the frontend process of building risk-based detection rules can take some time, the overall benefits you get from them are worth it. 

Reduced Alert Fatigue

Alert fatigue is a real issue for anyone working in cybersecurity, and the problem has only gotten worse over the last few years. According to research, security teams are overwhelmed with inaccurate or unnecessary alerts, struggling to prioritize and review them effectively with:

  • 59% of respondents saying they receive more than 500 cloud security alerts per day
  • 43% saying more than 40% of their alerts are false positives
  • 56% saying they spend more than 20% of their day reviewing alerts and deciding which ones should be dealt with first
  • 55% saying that critical alerts are being missed

 

With risk-based alerting, you can correlate multiple events to generate fewer false positives. By reducing the overall number of alerts and making them more valuable, your security team can prioritize their responses better. 

 

Faster Investigation Times

With fewer alerts and better prioritization capabilities, your security team can investigate incidents faster. With more attributes added to the alert, the security team has a way to focus their investigations. For example, consider this risk-based alert that monitors for people who recently tendered their resignation who make changes to Active Directory:

By linking the organization’s HR information to its Active Directory, the security team has a way to monitor for a specific, high-risk use case more precisely. When the system generates the alert, they also have all the information necessary to investigate the root cause. 

Improved Security Metrics

Proving your security program’s effectiveness typically includes the following metrics:

  • Mean Time to Detect (MTTD)
  • Mean Time to Investigate (MTTI)
  • Mean Time to Contain (MTTC)
  • Mean Time to Recover or Mean Time to Remediate (MTTR)

 

With risk-based alerts, you reduce all of these times, ultimately improving the metrics. You can think of it like a chain reaction. With better detection, security teams work with better information and focus. With fewer overall alerts, analysts can investigate them faster. The faster they can find the incident’s root cause, the sooner they can contain the attacker, remediate the system, and get everything back online. 

Who benefits from risk-based alerts?

Even though risk-based alerts sit under the security function, various people across your organization benefit from them. 

Security Analysts

With better information, your security analysts can do their jobs more effectively and efficiently. Since they’re not spending as much time chasing down false alerts, they can focus their energy on high-impact activities like threat hunting. Further, when security analysts have the tools to do their job well, they’re more likely to stay with the company, reducing employee turnover. 

IT Help Desk

When something goes wrong in your environment, the help desk is the first place users turn. Often, security issues and operational issues mimic one another. For example, a Distributed Denial of Service (DDoS) attack slows down your network, but a network device configuration issue can have the same outcome. With security teams detecting and responding to incidents faster, your IT help desk gets fewer calls. 

Senior Leadership

Senior leadership is responsible for overseeing the organization’s compliance posture and making data-driven decisions about the cybersecurity program. Your risk assessment is the basis of your compliance program. With risk-based alerts, you can align your security and compliance objectives more effectively. Further, leadership needs to understand the program’s strengths and weaknesses to make meaningful decisions about security investments. When you map risk-based alerts to frameworks like MITRE ATT&CK, you gain visibility into potential tooling gaps.

Graylog Security: Risk-Based, High Fidelity Alerts to Mature Your Program

With Graylog Security, you can build risk-based, high fidelity alerts based on your organization’s unique technology stack and risk profile. Our cloud-native capabilities, intuitive UI, and out-of-the-box content enable you to build the security program you need without paying for the functionalities you don’t use. Using our prebuilt content, you gain immediate value from your logs wit search templates, dashboards, correlated alerts, dynamic lookup tables, and more. 

Built with end-users in mind, Graylog’s platform empowers people of all skill levels. You don’t need special skills or engineers to build the risk-based alerts so you can uplevel your security with your current team, reducing labor costs often associated with complex SIEMs. 

About Graylog  
At Graylog, our vision is a secure digital world where organizations of all sizes can effectively guard against cyber threats. We’re committed to turning this vision into reality by providing Threat Detection & Response that sets the standard for excellence. Our cloud-native architecture delivers SIEM, API Security, and Enterprise Log Management solutions that are not just efficient and effective—whether hosted by us, on-premises, or in your cloud—but also deliver a fantastic Analyst Experience at the lowest total cost of ownership. We aim to equip security analysts with the best tools for the job, empowering every organization to stand resilient in the ever-evolving cybersecurity landscape.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How to reset or change your Epic Games password

 

How to reset your Epic Games password

Forgot your Epic Games password and got locked out of your account? No problem! There’s an easy way to reset the password and regain access. Here’s what you need to do:

  1. Head to the login page on the Epic Games Store website or app.

  2. Click on “Forgot password?”

  3. Enter the email tied to your account to get a security code.

  4. Check your email for the code, then enter it on the site.

  5. Set up a new password that meets Epic Games’ security requirements, and click “Reset Password.”

  6. Use the new password to sign in again.

 

How to change your Epic Games password

If you suspect that your Epic Games password isn’t strong enough or simply want to change it (as recommended every 6 months to ensure account security), you can quickly do so by following a few steps on the Epic Games Store platform. Here’s how:

  1. Log in to your Epic Games account.

  2. Go to the “Account Info” page and find the “Password and Security” section.

  3. Enter your current password in the “Current Password” field.

  4. Create a new password, then confirm it by retyping it in the second box.

  5. Click “Save Changes.”

 

Best practices for creating a strong password

As mentioned earlier, a good habit is to change your passwords every 6 months, even if they’re strong. Why? Because regular updates make it harder for attackers to break in and access your accounts. So, if it’s been a while since you last updated your Epic Games password, now’s a great time to do it.

When creating a strong new password for Epic Games—or any other account—aim for at least 16 characters, mixing uppercase and lowercase letters, numbers, and symbols. Avoid using anything familiar, like phrases or personal information. The more random it is, the better.

And if creating and remembering such secure passwords sounds challenging, NordPass can help. It can generate strong passwords for you on the spot and store them securely in an encrypted vault that only you can access. With NordPass, you can log in quickly and securely to your Epic Games account without sacrificing security. Try it and see the difference it will bring to your online experience.

 

Frequently asked questions

 

What are the Epic Games password requirements?

Epic Games keeps its password requirements fairly simple: your password only needs to be at least 8 characters long, with at least one number and one letter, and no spaces. To better secure your account, though, we recommend that you go for a 16-character password that includes numbers, symbols, and a mix of uppercase and lowercase letters, all arranged randomly.

 

How often should I change my Epic Games password for security purposes?

It’s a good idea to change your Epic Games Store password, just like any other password, every 6 months to keep things secure. This makes it much harder for hackers to break in. And if creating complex passwords feels like a hassle, tools like NordPass’ Password Generator can handle it for you instantly.

 

How do I enable two-factor authentication (2FA) to protect my Epic Games account?

To set up two-factor authentication on your Epic Games account, all you need to do is just log in, go to the “Password & Security” section, and pick your 2FA method—an authenticator app, SMS, or email. This adds an extra layer of security by requiring a code from your chosen method each time you log in.

 

What should I do if someone else has changed my Epic Games password without my permission?

If you think or know for sure that someone has changed your Epic Games password without your consent, act quickly and follow these 3 steps to secure your account:

  1. Reset your password using the Epic Games password reset page or the account recovery page.

  2. Set a strong password for the email address linked to your Epic Games account.

  3. Enable 2FA on your Epic Games account to add an extra layer of security.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.