# Android Passcode **Last Updated On**: 13 Jul 2026 **19 minutes read** You can define the parameters for creating a passcode and configure the passcode settings on Android devices here. The MDM password expires after the **Maximum passcode age** set by the administrator. After expiry, the user is enforced to change the password. The user should unlock the device using the expired password in order to change it, while other device functionalities are restricted. During the final few days until expiry, the user will be reminded to change the password. **Note:** For Android 11 devices even if a PIN is applied to unlock the device, a password keyboard will pop up by default. **Only devices running Android 5.0 or above can be provisioned as [Profile Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Profile_Owner) or [Device Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Device_Owner).** ## Profile Description | FEATURE | DESCRIPTION | KNOX-ENABLED SAMSUNG | NON-SAMSUNG LEGACY | NON-SAMSUNG PROFILE OWNER | NON-SAMSUNG DEVICE OWNER | |---|---|---|---|---|---| | | | | | | | | **APPLY PASSCODE (Specify if you want the passcode to be applied to the whole device or only to the work profile container)** | | | | | | | Device | Passcode will be applied to the whole device. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | | Work profile (Applicable for devices running 7.0 or later versions) | Passcode will be applied only to the work profile container (created as the device is provisioned as Profile Owner). | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | | | | | | | | | **CONFIGURE** | | | | | | | Passcode requirements | You can select the conditions that need to be met when the users configure a passcode on devices. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | | Default passcode | You can set a mandatory common passcode for the devices, which users cannot modify. If a default passcode is configured, the end user may attempt to change it, but MDM will automatically revert it back to the enforced default. For example: If the default passcode is **1234** and the user changes it to **1111**, MDM will detect this change and reset it to **1234**. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | | Password removal | In the case of digital signage, organizations must set up the device without a passcode. Using this option, any existing passcode on the device can be removed and users can be prevented from manually configuring a passcode on these devices. **Not applicable for devices running Android 11.0 or above.** Note: Password set by the user cannot be removed from Samsung devices running Android 9.0 or above, enrolled via invite method. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | | FEATURE | DESCRIPTION | KNOX-ENABLED SAMSUNG | NON-SAMSUNG LEGACY | NON-SAMSUNG PROFILE OWNER | NON-SAMSUNG DEVICE OWNER | |---|---|---|---|---|---| | **PASSCODE COMPLEXITY (Applicable only for devices running Android 12.0 and above)** | | | | | | | Low | A Pattern or PIN should be configured with repeating or ordered sequence (Example: 4444, 1234, 4321, 2468). | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | | Medium | The passcode should contain a PIN with no repeating or ordered sequences (Example: 4857), alphabetic, or alphanumeric password with a length of at least 4 elements. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | | High | The passcode should contain a PIN with no repeating or ordered sequences and a length of at least 8 elements (Example: 49137258) or alphabetic or alphanumeric passwords with a length of at least 6 elements (Example: A7b9Z2). | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | > The remaining configuration options (Android 11 and below settings, Other Settings, Biometric Passcodes, Samsung-only controls, and all minimum/maximum constraints such as length, history, repetition, symbols, numeric sequence, Smart Lock, Temporary Passcode, Strong Authentication timeout, etc.) are supported as indicated in the original matrix and follow the same applicability pattern across: > > - Knox-enabled Samsung > - Non-Samsung Legacy > - Non-Samsung Profile Owner > - Non-Samsung Device Owner For Smart Lock trust agents, refer to: [On-Body detection, Trusted places/devices/voice](https://support.google.com/android/answer/9075927?hl=en) --- - After distributing this policy, the passcode must be set by the user on the device. Only after this will the *device details* view under **Inventory** be updated. - If the user doesn't configure the passcode before the duration specified in [Profile Settings](https://www.manageengine.com/mobile-device-management/help/enrollment/customize_me_mdm_app.html#Configure_Profile_Settings), then all the apps except ME MDM app, Launcher and Settings get disabled as [explained here](https://www.manageengine.com/mobile-device-management/help/enrollment/customize_me_mdm_app.html#passcode). - If the device already has a passcode set and it complies with the configured MDM policy, the user will not be prompted to create a new passcode. - With Android 12.0, you can configure passcode complexity levels to low, medium and high. If you want granular passcode requirements instead of predefined complexity levels, configure custom passcode settings. However, Google will deprecate these granular settings soon and it is not recommended for Android 12.0 and above. - If the passcode policy isn't applied on the device, verify whether other policies are controlling passcode configuration (for example, Exchange policies). Also verify if there are other device administrators controlling passcode policy by navigating to **Settings → Security → Other Security Settings → Device Administrators**. - In Samsung devices, if the device does not factory reset automatically after exceeding maximum failed attempts, it might be due to: - A factory reset restriction applied from MDM. Navigate to **Device Mgmt → Profiles → Android → Restrictions → Security** and ensure **Restore Factory Settings** is set to *Allow*. - An API restriction preventing factory reset by another device administrator. - If the admin distributes a profile with minimum passcode complexity, users can still choose to set a higher complexity passcode with a combination of digits and alphabets.