3.10 Ensure 'Require password' is set to 'True'

Information

This policy setting determines if a password is required for the device.

Rationale:

Allowing users to access a device without a password means that anyone with physical access to it can view data on the device.

Impact:

Users will have to re-enter their password each time they want to use their device.

Note: This is a mobile device management setting. Use caution when applying these settings as they could have adverse effects depending on the environment, and internal policies around bring your own device (BYOD). These policies could affect a user's BYOD.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MobileDeviceMailboxPolicy 'Profile' -PasswordEnabled $true

OR
Perform the following actions:

Launch the EAC (Exchange Administrative Center).

Go to 'Mobile' on the left and click on the 'Mobile device mailbox policies' tab.

Double-click the policy you wish to modify and go to the 'Security' settings.

Ensure the Require a password box is checked and click Save.

Default Value:

False

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Windows

Control ID: cc5d12499c7b51f0157d106ab27efbdf3d40ed4a338918056c2426714eda70ec