2.4.4 Ensure 'Maximum Auto-Lock' is set to '2 minutes' or less

Information

This recommendation pertains to the maximum number of minutes a device may remain inactive before auto-locking.

Note: This recommendation refers to maximum auto-lock, consistent with the interface language, but iOS and iPadOS devices treat the auto-lock function as equaling exactly 2 minutes.

Rationale:

Automatically locking the device after a short period of inactivity reduces the probability of an attacker accessing the device without entering a passcode.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Passcode tab.

In the right window pane, set the Maximum Auto-Lock to 2 minutes.

Deploy the Configuration Profile.

Additional Information:

This is not enforced during certain activities; such as watching movies.

See Also

https://workbench.cisecurity.org/benchmarks/15548