Profile: Passcode Policy
The "Passcode Policy" profile controls the passcode requirements enforced on a device, including minimum length and complexity, expiration, reuse prevention, auto-lock timing, and the number of failed attempts allowed before the device is erased or locked out.
Apple documentation for this feature is available here.
To create a Passcode Policy profile:
- Go to Configs > Profiles and click "Create Profile".
- From the list, select "Passcode Policy".
- Configure the settings as desired.
- Assign the configuration to your devices/groups.
Note: Only one Passcode Policy profile can be applied per device.
Passcode Policy settings explained
- Require Passcode on Device: Requires the device to have a passcode set. Enabled by default. Most other settings in this profile only take effect while this is enabled.
- Require alphanumeric value: Requires the passcode to contain at least one letter, in addition to numbers.
- Allow simple value: When disabled, prevents the use of repeating, ascending, or descending character sequences (e.g. "1111" or "1234") in the passcode. Allowed by default.
- Minimum length: The minimum number of characters required in the passcode. Set to "0" for no minimum.
- Minimum number of complex characters: The minimum number of non-numeric special characters required in the passcode.
- Maximum age in days: The number of days after which the device user must change their passcode. Set to "None" for no expiration.
- Passcode history: The number of previous unique passcodes that cannot be reused (0–50). Set to "0" to allow reuse.
- Maximum auto-lock time: The maximum amount of idle time allowed before the device automatically locks. Applies to both iOS and macOS.
- Maximum grace period before lock: The maximum amount of time a device can remain unlocked without requiring the passcode to be re-entered after it would otherwise lock. Applies to both iOS and macOS.
- Maximum number of failed attempts: The number of consecutive failed passcode attempts allowed before the device takes action. On iOS, this results in the device being erased; on macOS, this results in the account being locked. Set to "Infinite" to disable this limit.
- Minutes until failed login is reset: The amount of time after which the failed attempt counter resets to zero. Set to "None" to never reset automatically.
Note: This profile is delivered as a traditional (non-declarative) configuration profile and does not support Declarative Device Management (DDM). On macOS, it installs both a passcode policy and a screen saver password policy so that the configured grace period is also enforced when the screen saver activates.
Eric McCann
Was this article helpful?