Device Restrictions & Passcode Policies

Device Restrictions


The Restrictions profile configures restrictions on iOS, iPadOS, macOS, and tvOS devices. Features may vary based on the type and OS version of the device, and some may require supervision.

To create a Restrictions profile go to Management > Restrictions. Select the restrictions to be applied, and choose the Application time (Full time or according to a time profile). Assign the profile to users and/or devices and click Save.

If multiple Restriction profiles are installed on a device, the OS will combine all settings for the most restrictive configuration.

 

 

Common iOS/iPadOS Restrictions


Below is a list of common restrictions applied to iOS/iPadOS devices:

 

Common macOS Restrictions


The macOS Restriction profile is organized into six categories/tabs. Use the option 'Do not configure the options on this tab' in the Restrictions profile to ensure any settings or restrictions within the tab are not applied and the default or manual configuration that's present on the macOS devices will remain unchanged. This feature is important in prevention of accidental deployment of configurations and impact of devices assigned to the profile.

The tabs are organized with their corresponding restrictions. After making any changes to a Restriction profile and reinstalling the profile on devices, the Mac may require a reboot for the new restriction configurations to be applied.

macOS Restrictions Tabs

 

Passcode Policies


The Passcode Policies profile configures passcode criteria on iOS, iPadOS and macOS devices. It supports the system scope and user scopes on macOS devices. If user scope is chosen, please assign only users to the profile. If existing passcodes do not meet the policy standards, users will be prompted to reset their password.

The Passcode Policy profile does not create or set passcodes and is not compatible with Apple Shared iPad devices. To set the PasscodeLockGracePeriod on Apple Shared iPad devices, configure the Apple Shared iPad Shared Device Group settings.

To create a Passcode Policy, go to Management > Passcode Policies.

Features include:

Additional Considerations

 

Removing a passcode on iOS/iPadOS devices


If the passcode is forgotten on an iOS/iPadOS device, it's important to keep the device connected to the network and not restart the device. The device will remain auto-joined to the network as long as it has not been restarted or powered off. As long as the device remains connected it can receive the Remove Lock Passcode command from Mosyle to remove the passcode, Touch ID, and/or Face ID.

To remove the passcode from an iOS/iPadOS device go to Management > Devices Overview > Select the device > More dropdown menu: Remove Lock Passcode.

If the command is sent and the device is connected to the internet, it will remove the passcode and allow the device to be unlocked with the Home button. If the Passcode Policies profile is installed on the device to force a password, it will prompt the user to set a new passcode.

 

Managing User Accounts on macOS


Administrators can manage User Accounts on Mac computers that are supervised and enrolled in Mosyle.

To access these options, go to Management > Devices Overview > Click on a device's name to bring up the Device Information window > More dropdown: Manage Users. Here you can either change the user's password or unlock the user account after too many failed password attempts.

In order to change a user's password, Administrator credentials for an admin user with a Secure Token is required. The new password must meet password policies, including the Passcode Policies profile or active rules in Security. If FileVault is turned on, the disk must be unlocked for the device to acknowledge the commands. The device must be online at the login window in order for the commands to go through to change the user's password or unlock the device.

If the user's password is unable to be changed through Mosyle, the password can be changed using the Reset Password Assistant in recoveryOS. To reset an account's password, follow the instructions under the heading "Use the Reset Password assistant" in the Apple Support article.

Changing the ADE Admin Password

When creating the Administrator account using the Automated Device Enrollment profile, a password needed to be defined. This password can be changed by sending the Set Admin password in Devices Overview, or using the Single Shot profile to Change the Randomized DEP Admin Password.

 


Revision #1
Created 2025-10-08 00:29:27 UTC by joliveira
Updated 2025-10-08 00:30:44 UTC by joliveira