Enforcing Passcode Compliance for Mobile Devices

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

You can enforce passcodes on mobile devices to enhance security and protect sensitive information. This measure can significantly reduce the risk of unauthorized access when a device is lost or stolen. By requiring a passcode, you can help ensure that only authorized users can access corporate emails, documents, and other resources stored on the device, thus safeguarding against data breaches and maintaining compliance with privacy regulations.

Note:

For personally owned iOS and iPadOS devices enrolled with User Enrollment, you can require passcodes with a minimum of six characters and prevent users from using simple passcodes (e.g., "123456" or "abcdef"). However, you cannot require complex characters or passwords.

Use the Passcode payload to configure passcode compliance for local user accounts.

  1. On the Configuration Profiles page, do one of the following:
    • Click New to create a new configuration profile.

    • Select an existing configuration profile and click Edit .

  2. Click the Passcode payload.
  3. Jamf recommends configuring the following passcode settings for mobile devices:
    • Require PasscodeInclude
    • Complex PasscodeEnforce
    • Minimum Passcode Length6
    • Maximum Passcode Age360
    • Passcode History5
    • Maximum Auto-Lock5 minutes
    • Maximum Grace Period for Device Lock1 minute
  4. Click the Scope tab and configure the scope of the configuration profile.

    You can create a passcode-specific smart group to use as the scope target. For more information, see Recommended Smart Device Group Criteria.

  5. Click Save .
After the passcode settings have been saved, the result will look similar to the following screenshot: