2.21 Set 'Require password' to 'True'

Information

Passwords should be necessary to unlock mobile devices because they will help secure sensitive information stored on the devices in the event of loss or theft.

Rationale:

Allowing users to access devices without passwords means that anyone with physical access to them can view data on the devices.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MobileDeviceMailboxPolicy -Identity Default -PasswordEnabled $true

See Also

https://workbench.cisecurity.org/files/1512

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-19

Plugin: Windows

Control ID: 3eca5342c300a8e144e739caaf059083f220e99c03ce0e6621e369e7b0ed0daf