Lockout screen and password settings shall be configured for each device
Last updated
Last updated
Lockout screen timeouts should be configured for a certain number of minutes of activity for all device platforms. Password complexity requirements should be enforced and users should be prompted to change their password if it does not meet corporate requirements. In Intune, the location to configure these settings varies depending on the platform.
Windows: Security Baselines (Device Lock, Local Policies Security Options), Configuration Profiles (Device Restrictions: Password)
macOS: Compliance Policy (System Security)
iOS: Compliance Policy (System Security)
Android: Compliance Policy (System Security)
All supported devices have configuration settings defined/enforced for lockout screen timeouts and passwords
β’ Any tenant with Intune licensing can access this setting.
Windows Security Baselines:
Under Device Lock set the password requirements
Under Local Policies Security Options, Set the Minutes of lock screen inactivity until screen save activates policy
Under System Security, modify the Password requirements and minutes of inactivity before password required
Under System Security, modify the Password requirements and minutes of inactivity before password required
Under System Security, modify the Password requirements and minutes of inactivity before password required
End users who enroll devices into Intune after this policy is enforced may be prompted to update their password if the policy requirements are not met on the device.
macOS Compliancy Policy:
iOS Compliancy Policy:
Android Compliancy Policy: