The Passcode Device Setting includes a setting called Maximum failed attempts allowed before lock/erase that controls how many incorrect passcode attempts are allowed before macOS locks the account or iOS/iPadOS wipes the device. This is a CIS recommended security configuration and is included by default in Addigy's macOS and iOS/iPadOS Compliance benchmarks.
Platform Behavior
| Platform | Maximum attempts enforced | What happens |
|---|---|---|
| macOS | 5 | The account is locked after more than 5 failed attempts |
| iOS / iPadOS | 6 | The device is wiped after more than 6 failed attempts |
Note: These limits are enforced by Apple and cannot be set higher than the values above. For full details on this MDM key, see Apple's developer documentation.
Excluding This Setting from a Compliance Benchmark
If you do not want this setting included in your Compliance benchmark, you can clone the benchmark and remove the key. See How to Clone and Customize Pre-built Benchmarks for instructions.