2.6 Set 'Allow simple passwords' to 'False'

Information

You can configure this setting to require strong passwords to unlock mobile devices before they can connect via ActiveSync to an Exchange server.

Rationale:

Allowing simple passwords can make it easier for an attacker to correctly guess them.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MobileDeviceMailboxPolicy -AllowSimplePassword $false

See Also

https://workbench.cisecurity.org/files/1512

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(a)

Plugin: Windows

Control ID: 56b3d381a0e5b651dfc1dd6e037297aa39109a98e4a62f4b8d474ca5fbe0873a