3.4.4 Ensure 'Maximum Auto-Lock' is set to '2 minutes' or less

Information

This recommendation pertains to the maximum number of minutes a device may remain inactive before auto-locking.

Note: This recommendation refers to maximum auto-lock, consistent with the interface language, but iOS and iPadOS devices treat the auto-lock function as equaling exactly 2 minutes.

Rationale:

Automatically locking the device after a short period of inactivity reduces the probability of an attacker accessing the device without entering a password.

Impact:

This is not enforced during certain activities, such as watching movies.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Passcode tab.

In the right window pane, set the Maximum Auto-Lock to 2.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548