Set password requirements for managed mobile devices

As an administrator, you can protect your organization's data by requiring that managed devices have a screen lock or password. With advanced mobile management, you can set minimum password characteristics and require that users reset their password regularly. 

Understand the user impact

  • Users get a notification when their passwords don't comply with your requirements. Users have 24 hours to update their passwords. After that period, they can't access their work data until they set an acceptable password.
  • If you use basic management and require a password, users with Android 5.1.1 Lollipop and earlier devices need to install the Google Apps Device Policy app. Passwords are not enforced on Apple iOS 7 and earlier devices.

Set password requirements

Basic option: Require a screen lock or password

Before you begin: To apply the setting for certain users, put their accounts in an organizational unit.

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. From the Admin console Home page, go to Devices.
  3. Click SettingsPassword settings.
  4. To apply the setting to everyone, leave the top organizational unit selected. Otherwise, select a child organizational unit.
  5. Check the Require users to set a password box.
  6. Next to Password strength, select Basic (Any screenlock)
  7. (Optional) If you use basic mobile device management and want to require passwords on devices earlier than Android 6.0 Marshmallow, check the Require users of pre-Android 6.0 (Marshmallow) devices to set a password box.
  8. Click Save. If you configured a child organizational unit, you might be able to Inherit or Override a parent organizational unit's settings.
Advanced option: (Recommended) Require a strong password

Before you begin: To apply the setting for certain users, put their accounts in an organizational unit.

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. From the Admin console Home page, go to Devices.
  3. Click SettingsPassword settings.
  4. To apply the setting to everyone, leave the top organizational unit selected. Otherwise, select a child organizational unit.
  5. Check the Require users to set a password box.
  6. Choose a password strength:
    • Standard—Requires a PIN or password. Screen lock patterns are not accepted. A password can contain any characters in any order.
    • Strong—Requires at least one character, number, and symbol. (Not supported on Windows Phone 7 and 7.5 devices.)
  7. (Optional) If you select Strong, you can configure additional password requirements for Android devices. Check the Apply custom strength settings for Android box and select the requirements.
  8. For Minimum number of characters, enter a minimum password length. Strong passwords should have 3 or more characters.
  9. (Optional) To prompt users to reset their password regularly, check the Number of days before password expires box and enter the number of days. Supported on Android 3.0 Honeycomb and later devices.
  10. (Optional) To prevent the reuse of expired passwords, check the Number of expired passwords that are blocked box and enter the number of previous passwords that can’t be used again.  For example, enter 2 to block the user from reusing their last 2 device passwords. Supported on Android 3.0 and later devices.
  11. (Optional) To lock the device screen after it's inactive for some time, select a time from the Automatically lock the device after menu.

    This setting overrides mobile devices' default values: for Apple iPhone devices, the default is 5 minutes. For iPad devices, the default is 15 minutes.

  12. (Optional—Use with caution) To automatically wipe a device when a user enters too many incorrect passwords, check the Wipe device after failed attempts box and enter the number of attempts allowed.

    For example, if you enter 5, then 4 failed attempts are allowed. After the fifth, the device is wiped and reset to its factory settings.

    Note: This option doesn't apply to devices that use Google Sync.

  13. (Optional) If you want to require passwords on devices earlier than Android 6.0 Marshmallow, check the Require users of pre-Android 6.0 (Marshmallow) devices to set a password box.
  14. Click Save. If you configured a child organizational unit, you might be able to Inherit or Override a parent organizational unit's settings.
Less secure option: (Not recommended) Turn off password requirements

Before you begin: To apply the setting for certain users, put their accounts in an organizational unit.

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. From the Admin console Home page, go to Devices.
  3. Click SettingsPassword settings.
  4. To apply the setting to everyone, leave the top organizational unit selected. Otherwise, select a child organizational unit.
  5. Uncheck the Require users to set a password box.
  6. Click Save. If you configured a child organizational unit, you might be able to Inherit or Override a parent organizational unit's settings.

Related topics


Google, G Suite, and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated.

Was this helpful?
How can we improve it?