2.4.5 Ensure 'Maximum number of failed attempts' is set to '6'

Information

This recommendation pertains to the number of attempted logins before the automatic deletion of a device's cryptographic key.

Rationale:

Excessive incorrect passcode attempts typically indicate that the owner has lost physical control of the device. Upon such an event, erasing the encryption key will help to ensure the confidentiality of information stored on the device.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left windowpane, click on the Passcode tab.

In the right windowpane, set the Maximum number of failed attempts to 6.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/files/3064