When a non-Mac device is managed using Account Driven User Enrollment, the device management server has limited capabilities related to the passcode. When User Enrollment was first introduced, installing a configuration profile containing a passcode payload would ignore all the keys in the payload and instead require a minimum of a non-simple 6 digit PIN. Starting in iOS 17 and aligned releases of other platforms, if the payload contains a maxInactivity key its value is ignored, however it removes the Never option from Settings > Display & Brightness > Auto-Lock. It's still possible for the user to select a shorter duration for Auto-Lock. The Apple documentation for the Passcode payload does not currently explain this. We're working on updating that documentation. Thank you for raising this issue, which helped us discover the omission. I don't know whether Microsoft Intune supports this maxInactivity key in this scenario. It's possible that Microsoft did not add support fo
Topic:
Business & Education
SubTopic:
Device Management
Tags: