Profile: Passcode Policy

The "Passcode Policy" profile controls the passcode requirements enforced on a device, including minimum length and complexity, expiration, reuse prevention, auto-lock timing, and the number of failed attempts allowed before the device is erased or locked out.

Apple documentation for this feature is available here.

To create a Passcode Policy profile:

  1. Go to Configs > Profiles and click "Create Profile".
  2. From the list, select "Passcode Policy".
  3. Configure the settings as desired.
  4. Assign the configuration to your devices/groups.

Note: Only one Passcode Policy profile can be applied per device.

Passcode Policy settings explained

  • Require Passcode on Device: Requires the device to have a passcode set. Enabled by default. Most other settings in this profile only take effect while this is enabled.
  • Require alphanumeric value: Requires the passcode to contain at least one letter, in addition to numbers.
  • Allow simple value: When disabled, prevents the use of repeating, ascending, or descending character sequences (e.g. "1111" or "1234") in the passcode. Allowed by default.
  • Minimum length: The minimum number of characters required in the passcode. Set to "0" for no minimum.
  • Minimum number of complex characters: The minimum number of non-numeric special characters required in the passcode.
  • Maximum age in days: The number of days after which the device user must change their passcode. Set to "None" for no expiration.
  • Passcode history: The number of previous unique passcodes that cannot be reused (0–50). Set to "0" to allow reuse.
  • Maximum auto-lock time: The maximum amount of idle time allowed before the device automatically locks. Applies to both iOS and macOS.
  • Maximum grace period before lock: The maximum amount of time a device can remain unlocked without requiring the passcode to be re-entered after it would otherwise lock. Applies to both iOS and macOS.
  • Maximum number of failed attempts: The number of consecutive failed passcode attempts allowed before the device takes action. On iOS, this results in the device being erased; on macOS, this results in the account being locked. Set to "Infinite" to disable this limit.
  • Minutes until failed login is reset: The amount of time after which the failed attempt counter resets to zero. Set to "None" to never reset automatically.

Note: This profile is delivered as a traditional (non-declarative) configuration profile and does not support Declarative Device Management (DDM). On macOS, it installs both a passcode policy and a screen saver password policy so that the configured grace period is also enforced when the screen saver activates.

Was this article helpful?