# iOS DDM Passcode Settings Last updated: August 14, 2026 The passcode, being the first line of security for devices, organizations would want to set passcodes adhering to their security standards, ensuring certain aspects like the minimum length and complexity requirements. You can define the parameters for creating a passcode by configuring the Passcode profile. ## Profile Description **Require Passcode on Device:** Enabling this setting requires users to configure a passcode on the device. If the device already has a passcode that meets the configured requirements, users will not be prompted to change it. ![](https://cdn.manageengine.com/sites/meweb/images/mobile-device-management/images/ddm-ios-profile-3.png) ![](https://cdn.manageengine.com/sites/meweb/images/mobile-device-management/images/ddm-passcode.png) **Require Alphanumeric Passcode:** Requires the device passcode to include both letters and numbers, preventing the use of numeric-only passcodes. **Require Complex Passcode:** Requires the passcode to meet complexity requirements by including a minimum number of complex (special) characters. **Minimum Passcode Length:** Specifies the minimum number of characters required for the device passcode. This can range from 4 to 16. **Minimum Complex Characters:** Specifies the minimum number of special characters that must be included in the passcode. This can range from 1 to 4. **Maximum Idle Time Allowed Before Auto-Lock:** Defines the maximum period of inactivity before the device automatically locks. If the specified duration is unsupported by the device OS, the closest supported value is applied. **Maximum Time to Unlock Device Without Passcode:** Specifies the maximum duration after the device locks during which users can unlock it without entering the passcode. If biometric authentication is enabled, this setting is overridden and the device requires immediate authentication. **Maximum Number of Failed Attempts:** Specifies the maximum number of incorrect passcode attempts allowed before the device applies Apple's security action, such as locking or erasing the device based on system configuration. This can range from 3 to 9. **Maximum Passcode Age:** Defines the maximum number of days a passcode can be used before users are required to set a new one. This can range from 1 to 730 days. **Number of Passcodes to be Maintained in History:** Specifies how many previously used passcodes are remembered to prevent users from reusing recent passcodes. This can range from 1 to 50 passcodes.