Device passcode policy for iOS
The passcode configuration profile controls the use of device passcode protection, including passcode requirements. When a device has the profile set, the device user must use a passcode to meet the requirements.
Creating a passcode policy
Follow these steps to create a passcode policy for managed iOS devices:
Defining the configuration
Setting | Description |
---|---|
Allow simple value | Allows the use of repeating, ascending, and descending character sequences in the passcode. |
Require alphanumeric value | Requires to use a combination of numbers and letters in the passcode, with at least one letter present. |
Minimum length | Defines the minimum required amount of characters in the passcode. |
Minimum number of complex characters | Defines the minimum required amount of non-alphanumeric characters required in the passcode, such as * or !. |
Setting | Description |
---|---|
Expiration age | Defines the time after which the passcode must be changed. |
Maximum screen lock timeout | Defines the maximum amount of time in minutes after which the device is automatically locked. |
History restriction | Defines the number of unique new passcodes required before reusing an old one. For example, if this value is set to 1, the passcode can be changed to the same passcode as the current one. If the value is set to 2, the first time the passcode is changed, it needs to be different than it currently is. The next time it is changed, the first passcode can be used again. |
Require passcode to unlock (after) | Defines the maximum amount of time the device can be unlocked without a passcode after locking. For example, if this value is set to 1 minute, the device can be locked and unlocked without using the passcode for 1 minute. After 1 minute, the device prompts for the passcode to unlock. |
Maximum number of failed attempts | Defines the number of attempts for entering incorrect passcodes before all data is erased from the device. |