WeGuard provides administrators with two levels of password management: Restrictions, which define the rules for user-created passwords, and Enforcement, which allows an administrator to push a specific password to all devices in a policy group. This ensures that managed devices always meet organizational security and compliance standards.
Navigate to Password Settings
Before defining restrictions or enforcing a reset, follow these steps to access the correct configuration panel:
Navigate to Policies and select the required policy you wish to modify from the list and click on its name to open the editor.
On the left-side settings panel, click on the "Password" tab.
Defining Password Restrictions
Configure the following requirements and lock settings:
-
Password Quality: Sets the minimum complexity required for the device password (e.g., Numeric, Alphanumeric, or Complex)
-
Max Failed Passwords: Defines the number of failed attempts allowed before the device is wiped (setting this to 0 means there is no limit).
-
Minimum Password Length: Specifies the mandatory number of characters (between 4 and 16) required for any new password.
-
Password Expiration Timeout: Determines how many days a password remains valid before a change is mandatory (setting this to 0 means it never expires).
-
Password History Length: Sets the number of previous passwords the system should remember to prevent users from reusing them.
-
Maximum Time to Lock: Defines the duration of inactivity allowed before the device automatically locks its screen.
Enforcing a Mandatory Password
The Enforce Reset Password feature is a powerful tool used to override current device states and push a specific, uniform password to an entire fleet immediately.
Step-by-Step Implementation:
Locate the Field: Scroll to the bottom of the Password tab to find the Enforce Reset Password field.
-
Enter the New Password: Type the specific password (e.g., 1234) you want to apply to all devices.
-
Initiate Save: Click the Save button in the top-right corner of the console.
Review and Confirm: A Review Changes window will appear, listing "Enforce Reset Password" as a pending change. Click Confirm & Save to broadcast the password to the entire fleet.