Work profile passcode
On this page
This configuration is used to define the password requirements for the work profile of Android Enterprise devices. Requirements for the device lock are defined via the Device password → configuration.
Supported Enrollment Types
The Work profile and Personal profile badges in the form indicate the enrollment types for which the configuration is supported:
- Devices with a work profile →
- Managed devices with a personal profile →
There is no profile selection. In both cases, the password requirements apply to the work profile.
Passcode Quality
Defines the required quality or type of screen lock or password. The selected level is a minimum requirement, passwords of a higher quality level are accepted as well.
The following options are available:
Complex (strong)
The password must contain at least one letter, one digit, and one special character. When this option is selected, the following additional mandatory fields are displayed (lowest permitted value in parentheses):- Minimum number of letters (1)
- Minimum number of lower case letters (0)
- Minimum number of upper case letters (0)
- Minimum number of non letters (0)
- Minimum number of numeric characters (1)
- Minimum number of symbols (1)
The fields are empty in a new configuration. The configuration can only be saved once all fields have been filled in.
Alphanumeric
The password must consist of letters and numbers.Alphabetic
The password must contain at least letters (or symbols).Numeric complex
Requires a numeric password with increased requirements, for example without simple or easy-to-guess number sequences.Numeric
The password must contain at least digits (e.g. a PIN).Pattern
Despite its name, this option does not enforce an unlock pattern. Any lock is sufficient (e.g. pattern, PIN, or password), and there are no requirements regarding its content.Biometric (weak)
A weaker biometric unlock method can be used, if supported by the device. With this selection, the fields Minimum passcode length, Maximum passcode age (in days), Passcode history and Number of failed passcode attempts before all data is erased are hidden and cannot be configured.
Minimum Passcode Length
Defines the minimum number of characters required for the password. The field is mandatory. The default value and the smallest permitted value is 4.
Example:
4→ The password must be at least 4 characters long.
Maximum Passcode Age (in Days)
Determines after how many days the password must be changed.
Number of days until a new password must be set. If the value is set to 0, the password never expires.
Example:
0→ No password expiration.
Passcode History
Defines how many previously used passwords may not be reused.
Number of stored and previously used passwords that may no longer be used again.
Example:
0→ There is no restriction on password reuse.
Number of Failed Passcode Attempts Before All Data Is Erased
Defines after how many incorrect password attempts a reset or wipe is triggered.
If no value is set, no automatic wipe is usually performed.
Disable Work Profile Apps Until User Complies with Password Requirements
If this option is enabled, apps in the work profile remain disabled until the configured password meets the defined requirements. The option is enabled by default.
The period after which blocking and wiping take place if the password requirements are not met is defined in the Compliance enforcement → configuration. By default, only the apps in the work profile are blocked. When wiping, only the work profile is removed on devices with a work profile (BYOD); devices with a personal profile (COPE) are reset to factory settings.
Require Separate Passcode for the Work Profile
If enabled, a separate passcode must be set for the work profile.
If this option is disabled, the same device screen lock may be used in some cases.
Notes
- These settings apply exclusively to the work profile, including on managed devices with a personal profile (COPE).
- Not all options are available to the same extent on every device or Android version.
- Actual enforcement depends on the manufacturer, Android version, and device mode.