> For the complete documentation index, see [llms.txt](https://docs.cubilock.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cubilock.com/profile-management/privacy-settings/password-constraints.md).

# Password Constraints

CubiLock allows you to define the password constraints required for device security. The password policy helps ensure users set secure passwords for their managed devices. These constraints can be set from the **Privacy Settings** under **Password Constraints** in your **Device Profile** configuration.

**To Add a Password Constraint:**

1. **Go to Privacy Settings**:\
   Navigate to the **Privacy Settings** section of the device profile, where you can see **Password Constraints**.

<figure><img src="/files/KEAfoAPCLJPwbUpHOKn2" alt=""><figcaption></figcaption></figure>

* **Click on "Add Constraint"**:\
  You'll see an **"Add Constraint"** button at the top-right of the Password Constraints section. Click on this to create a new password policy.
* **Define Password Policy Settings**:\
  The following fields are available for configuring your password constraints:
  * **Password Policy Scope**:
    * **Unspecified**: No specific requirement for the password scope.
    * **Scope Device**: The password requirement applies to the device.
    * **Scope Profile**: The password requirement applies to the user profile.

<figure><img src="/files/31moIEUBeCSU3E4ZyhGH" alt=""><figcaption></figcaption></figure>

**Password Quality**:\
Set the required quality of the password. The available options include:

* **Unspecified**
* **Biometric Weak**: A password based on a low-security biometric method.
* **Something**: No specific requirements, just a password.
* **Numeric**: Requires numeric-only passwords.
* **Numeric Complex**: Numeric passwords must be complex (no repeated numbers or ordered sequences).
* **Alphabetic**: Requires alphabetic characters.
* **Alphanumeric**: A combination of both numeric and alphabetic characters.
* **Complex**: A stronger password that meets several minimum security requirements.

<figure><img src="/files/74dBmNyqVOIgKaAd8028" alt=""><figcaption></figcaption></figure>

**Additional Settings**:

* **Password Expiration Time Out**: The number of days before the password must be reset.
* **Maximum Failed Passwords For Wipe**: Defines the number of incorrect password attempts before the device is wiped.
* **Require Password For Unlock**: Specifies if a password is required to unlock the device after a specific duration. The options include:
  * **Unspecified**
  * **Scope Device**
  * **Require Every Day**

<figure><img src="/files/XQ29FSbfTO7Oi8ayODbA" alt=""><figcaption></figcaption></figure>

1. **Save**:\
   After configuring the settings, click **Add** to apply the password policy.

**Example Configuration:**

You might configure a policy with **Password Quality** set to **Numeric**, **Password Policy Scope** set to **Scope Device**, and a **Maximum Failed Passwords For Wipe** value of **8**.

<figure><img src="/files/aCNKFWMQL6hwFOU2tb44" alt=""><figcaption></figcaption></figure>
