
Require password
Check this box if you wish to require a password on the device. It is disabled by default.
Allow device to save 'Recovery Password' to server
Enable this option if you wish to allow clients to use ActiveSync's Recovery Password option, which allows a device to save a temporary recovery password to the server to unlock the device if the password is forgotten. The administrator can find this recover password under the client's Details. Most devices do not support this feature.
Password Type
Simple PIN
How this option is implemented is largely dependent on the device, but selecting Simple PIN as the password type generally means that no restrictions or complexity requirements are placed on the device password, other than the Minimum password length option below. This allows simple passwords such as: "111," "aaa," "1234," "ABCD" and the like.
Complex/Alpha-Numeric
Use this policy option if you wish to require more complex and secure device passwords than the Simple PIN option. Use the Complexity level option below to define exactly how complex the password must be. This is the default selection when a password is required by the policy.
Password Strength
Minimum length
Use this option to set the minimum number of characters that the device password must contain, from 1-16. This option is set to "1" by default.
Complexity level
Use this option to set the complexity level requirement for Complex/Alpha-numeric device passwords. The level is the number of different types of characters that the password must contain: uppercase letters, lowercase letters, numbers, and non-alphanumeric characters (such as punctuation or special characters). You can require from 1-4 character types. For example, if this option were set to "2", then the password must contain at least two of the four character types: uppercase and numbers, uppercase and lowercase, numbers and symbols, and so on. This option is set to "1" by default.
Password Options
Days until password expires (0=never)
This is the number of days allowed before the device's password must be changed. This option is disabled by default (set to "0").
Number of recent passwords remembered/disallowed by device (0=none)
Use this option if you wish to prevent the device from reusing a specified number of old passwords. For example, if this option is set to "2" and you change your device password, you will not be able to change it to either of the last two passwords that were used. The option is disabled by default (set to "0").
Minutes of inactivity before device locks (0=never)
This is the number of minutes that a device can go without any user input before it will lock itself. This password option is disabled by default (set to "0").
Wipe device or enter 'Timed Lockout Mode' after repeated failed password attempts
When this option is enabled and the user fails the designated number of password attempts, the device will either lock itself for a certain amount of time or perform a wipe of all data, depending on the device. This option is disabled by default.
Failed password attempts before device wipes or enters 'Timed Lockout Mode'
When the "Wipe device.." option above is enabled and a user fails this many password attempts, the device will be wiped or the 'Timed Lockout Mode' will be triggered, depending on the device.
|