Skip to main content

How Require Passcode Settings Affect Jamf Now Managed Devices

Updated over 2 weeks ago

Description

The Blueprints > Security > Require Passcode checkbox (and its sub-options) provide the following device management capabilities:

  • Require devices in a Blueprint to set a password/passcode.

  • Enforce specific complexity requirements for passwords/passcodes.

macOS and iPadOS/iOS devices respond differently when these requirements are enforced. The following sections outline what to expect when enabling password/passcode requirements in Jamf Now.


Require Passcode Setting for iPadOS/iOS

When the Require Passcode security profile is installed on iPadOS/iOS devices, users are immediately prompted to set a new passcode if one is not present. This prompt also appears if the existing passcode no longer meets the requirements specified in the Blueprint. The MDM-enforced passcode prompt displays the following message:

"You must set an iPad unlock passcode within X minutes"

If the user does not set a passcode within the given time frame, they will be forced to do so once the timer expires.

This photo shows the pop-up that you should find on your device asking you to set a iPad passcode within the given timeframe.

Note that the Prevent Changes to Passcode restriction (located under Blueprints > Restrictions > Security & Privacy) will prevent the Jamf Now MDM prompt from forcibly setting a passcode. To ensure the Jamf Now MDM prompt appears and forces the user to set a passcode, this restriction must be disabled. You can do this by temporarily disabling the restriction in the current Blueprint or by assigning the device to a new Blueprint that does not have the Prevent Changes to Passcode restriction enabled.


Require Passcode setting for macOS

By default, macOS requires local passwords for any local account on the Mac. The Blueprints > Security > Require Passcode setting for macOS does not prompt the user to update their password when it becomes non-compliant. macOS enforces the password requirements specified in the Blueprint only in the following situations:

  • During any password change attempt (most commonly via System Settings > Users & Groups).

  • When the Blueprints > Security > Require Passcode > Maximum Passcode Age setting is enabled. Once the password age time expires, the user will be prompted to set a new password that meets the requirements specified in the Blueprint. The password age countdown starts when the Maximum Passcode Age profile is installed on the device.

This photo shows you the pop-up that you will see on your Mac device asking you to Reset Password.

Did this answer your question?