7.13 Ensure mobile devices require the use of a password

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

You should require your users to use a password to unlock their mobile devices.

Rationale:

Devices without this protection are vulnerable to being accessed physically by attackers who can then steal account credentials, data, or install malware on the device.

Impact:

This change will require users to provide a password to unlock their mobile device after the timeout period expires

Solution

To set mobile device management profiles, use the Microsoft 365 Admin Center:

Select Device Management under Admin Centers.

Select Device configuration and then under Policy select Configuration profiles

Select Create profile

Set a Name for the policy, choose the appropriate Platform and select Device restrictions

In the Password section, ensure that Password is set to Require.

Default Value:

This setting is not enabled by default.

See Also

https://workbench.cisecurity.org/files/4073