Category filter

Password Policy for Windows devices

Password protects your computer from unauthorized access and ensures device security for the critical data in it. With Hexnode MDM, admins can enforce strong password rules on Windows devices, thereby ensuring security to the organization’s data. This feature enables you to configure the level of complexity enforced on device passwords. When a password policy is pushed to a device, the user is asked to set a password that complies with the criteria defined. There are different scenarios for setting up a password policy for Windows:

  1. If the device does not have a password: A message will be displayed asking the user to set a device password based on the password rules pushed to the device via policy.
  2. If the device has a password and it complies with the set password rules: The change password pop-up shows up on the device when a user logs in for the first time after the password policy is associated. The pop-up will be shown even if the device already has a password that meets the constraints mentioned in the policy.
  3. If the device has a password but it does not comply with the set password rules: A message reading ‘The user’s password must be changed before signing in’ will be displayed.
Note


This feature is available on Enterprise, Ultimate, and Ultra subscription plans.

Configure Password settings from MDM console

To configure password rule for the users and make the password mandatory on the devices,

  1. Login to your Hexnode MDM portal > Navigate to Policies tab > Click on New Policy to create a new one or click on any policy to edit an existing one > Enter the Policy Name and Description in the provided fields.
  2. Navigate to Windows > Select Password > Click on Configure
  3. Configure Password settings.
    Password settings

    Password settings Supported OS Description
    Allow simple value
    PCs & Tablets Phones
    10
    8.1
    10
    Select this option to enable users to set simple passwords (without special characters or numbers) on their devices.
    Password type
    PCs & Tablets Phones
    10
    8.1
    10
    Select the type of password that the users can set on their Windows devices.

    Alphanumeric password: Enforce users to set an alphanumeric password.

    Numeric password: Enforce users to set a numeric password.

    Users can choose (default): Select this option to allow users to set a password according to their desire.

    Minimum password length
    PCs & Tablets Phones
    10
    8.1
    10
    Select the minimum number of characters required for the password.

    You can set any value in the range 4 – 16.

    Default value is 4 for mobiles and desktops.

    Note


    Local accounts will always enforce a minimum password length of 6.

    Minimum complex characters Select the minimum number of complex characters that the password should have.

    You can choose any value from,

    • Digits only (default)
    • Digits and lowercase letters
    • Digits, lowercase and uppercase letters
    • Digits, special characters, lowercase and uppercase letters
    Notes
    • Desktop local accounts enforce Digits, lowercase and uppercase letters, regardless of choice.
    • Desktop Microsoft accounts only supports either Digits only or Digits and lowercase letters.
    • Desktop Domain accounts are not supported.

    Maximum password age (in days)
    PCs & Tablets Phones
    10
    8.1
    10
    Select the maximum number of days before which the password needs to be changed.

    You can set any value in the range of 0 – 730 days.

    Note


    Passwords do not expire if the value is set as 0.

    Auto-lock (in minutes)
    PCs & Tablets Phones
    10
    8.1
    10
    Set the maximum duration of device inactivity after which the device gets locked automatically.

    You can set any value in the range of 0 – 999 minutes.

    Note
    • Devices will not be auto-locked if the value is set as 0.
    • Lumia 950 and 950XL auto-locks after 5 minutes, regardless of the value set by this policy.
    • You cannot disable the Auto-lock option on Windows 8.1 devices, as Never option is not present on them. However, on selecting 0 for Auto-lock from the Hexnode portal, the device gets locked only after 30 seconds, which is the lowest possible value shown on the Windows device lock settings screen.

    Configure auto-lock settings on Windows devices for endpoint security

    Users are prompted to enter the correct password on the device

    Device prompts the user to enter a random generated phrase after failed passcode attempts

    Password history
    PCs & Tablets Phones
    10
    8.1
    10
    Password history is set to block the users from reusing the password for a specified number of times.

    You can set any value in the range 0 – 50.

    Note


    Passwords do not expire if the value is set as 0.

    Failed attempt before wipe
    PCs & Tablets Phones
    10
    8.1
    10
    The number of wrong password attempts after which the device will be automatically reset to factory default settings and all user data (contacts, files, calendars, etc.) will be lost.

    You can set any value in the range 4 – 16 for desktops and 0 – 999 for mobile devices.

    Notes
    • Devices will not be wiped if the value is set as 0.
    • On mobile devices, the device is wiped when the user reaches the specified value.
    • On Windows 10 PCs and tablets, the policy would fail if BitLocker protection is not enabled on the devices. The device enters a recovery mode instead of being wiped. From here, you can restore the access to the device by using a 48-digit recovery code provided by the Organization.

  4. Finally, go to Policy Targets > + Add Devices > Select the required device(s) to which the policy needs to be associated > Click OK
  5. Click Save.

configure password policy for Windows devices using Hexnode mdm

Associate policy with Windows devices

To associate the policy with target devices, navigate to the Policies tab.

  • When the policy is not yet saved,
    1. Go to Policy Targets.
    2. Click on Devices > + Add devices, select the required devices and click OK to associate the policy with the target devices.
  • When the policy has already been saved,
    1. Select the appropriate policy.
    2. Then click on Manage > Associate Targets > choose the target devices and click on Associate to associate the policy with the target devices.
Notes:

  • On Windows 10 devices, password configurations get enforced only during the next restart. After the restart, the device mandates the user to configure the password based on the password requirements before signing in.
  • Once you disassociate the password policy from the device(s), a pop up appears on the device screen showing that the device no longer requires a password.

  • Managing Windows 10 Devices