Device password

This configuration defines the password requirements for the lock of the entire device.

The Device password configuration defines the requirements for the device lock of Android Enterprise devices. The requirements apply to the entire device. Requirements for a separate work profile password are defined via the Work profile passcode → configuration instead.


Difference from the Work Profile Password

Both configurations use the same form for the password requirements but differ in scope:

Device passwordWork profile passcode
ScopeDevice lock (entire device)Work profile only
Badges in the formnoneWork profile, Personal profile
Fully managed devicesappliedignored by the server
Additional optionsnoneDisable work profile apps until user complies with password requirements, Require separate passcode for the work profile

Both configurations can be part of the same policy. Relution then transfers both requirements to the device: one for the device and one for the work profile.

Fully managed devices → have no work profile. A Work profile passcode configuration is not transferred to them; the device lock is controlled exclusively via Device password.


Supported Enrollment Types

The form shows no badges, so the configuration is not restricted to specific enrollment types. It is available for all Android Enterprise enrollment types:


Passcode Quality

Minimum complexity that has to be fulfilled when a password is set. For a new configuration, Numeric is preselected.

The following options are available:

  • Complex (strong)
    The password must contain at least one letter, one digit and one special character. With this selection, the following additional mandatory fields appear (smallest permitted value in brackets):

    • Minimum number of letters (1)
    • Minimum number of lower case letters (0)
    • Minimum number of upper case letters (0)
    • Minimum number of non letters (0)
    • Minimum number of numeric characters (1)
    • Minimum number of symbols (1)

    The fields are empty for a new configuration. The configuration can only be saved once all fields are filled in.

  • Alphanumeric
    The password must contain digits and letters (or symbols).

  • Alphabetic
    The password must contain letters (or symbols).

  • Numeric complex
    The password consists of digits without repeating or ordered sequences. The portal shows the hint: “The user must have entered a password containing at least numeric characters with no repeating (4444) or ordered (1234, 4321, 2468) sequences.”

  • Numeric
    The password must contain digits.

  • Pattern
    Despite the name, no unlock pattern is enforced. Any kind of lock must be set up (e.g. pattern, PIN or password); there are no requirements regarding its content.

  • Biometric (weak)
    The device must at least be secured with a low-security biometric unlock method. With this selection, all other fields are hidden.


Minimum Passcode Length

Defines the minimum number of characters for the password. The field is mandatory and prefilled with 4. The smallest permitted value is also 4.


Maximum Passcode Age (in Days)

The maximum number of days until a new password has to be set. If the value 0 is specified, the password never expires. The field is mandatory and prefilled with 0.


Passcode History

Number of already used passwords that are saved and cannot be used again. The field is mandatory and prefilled with 0, meaning there is no restriction on reuse.


Number of Failed Passcode Attempts Before All Data Is Erased

Defines after how many incorrect entries the data is erased. The smallest permitted value is 1. The field is optional: if no value is set, the data is never erased.


Behavior on Non-Compliance

If the device password does not meet the requirements, the device reports a compliance violation. The period after which the device is blocked and reset as a result is defined in the Device passcode row of the Compliance enforcement → configuration. This row applies to fully managed devices and managed devices with a personal profile. On devices with a work profile, the Work profile passcode row applies instead. Without a custom rule, the default periods apply.

An option to disable apps until the requirements are met is only offered by the Work profile passcode configuration.


Notes

  • The Device password configuration can only be added once per policy.
  • Not all options are available to the same extent on every device or Android version.
  • Actual enforcement depends on the manufacturer, Android version and enrollment type.
Top