Enforcing Password and PIN Use

The VMP Server provides configuration options to ensure that all smartphone users are required to protect the device with a password. Additional options specify that Vocera Smartbadge users must provide a four-digit Personal Identification Number (PIN) to access their device, and that Vocera Collaboration Suite users must provide a PIN when accessing the app on either shared devices or all devices.

These options ensure that your confidential internal information is protected if the device is lost or stolen.

  1. Start the VMP Administrator: All Programs > VMP > VMP Administrator
  2. Type admin (or your administrative credentials) in the VMP Login dialog, and click OK.
  3. Select Configuration > System Options.

    The System Options dialog box appears.

  4. Scroll to the Security section of the options.
  5. To enforce the use of a PIN for Vocera Collaboration Suite users, set the Enforce App PIN option to one of the following:
    • SHARED: Require the use of a PIN on shared devices only.
    • ON: Require all users to supply a PIN. Users of personal devices must have their username and password credentials to supply the PIN, or they will be locked out of the Vocera Collaboration Suite application.

    If Enforce App PIN is set to OFF, VCS users are not required to supply a PIN.

  6. To enforce the use of a PIN for Vocera Smartbadge users, set the Enforce Smartbadge PIN option to Yes.

  7. If Enforce App PIN or Enforce Smartbadge PIN has been selected, set PIN Timeout to the amount of time, in seconds, that the device can remain idle before the PIN must be entered again.
  8. To enforce a device password for all smartphones, set the Enforce device password for all smartphones option to ON. To enforce a device password for shared smartphones only, set this option to Shared.

    Configure the following options:

    Option Description
    Minimum Password Length Enter the number of characters the user must include in the device password. For iPhone users, the device Passcode Lock settings must be changed if you want a password longer than 4 numerical digits.
    Require at least one letter Select Yes to ensure that the user adds at least one letter to the device password. For iPhone users, you cannot insist on a password with at least one letter. For iPhone users, the device Passcode Lock settings must be changed if you want a password to include a letter.
    Auto Lock Set the duration of inactivity, in minutes and seconds, until the device auto-locks. In the following example, the device is set to auto-lock after five minutes and thirty seconds:

    5m30

    Enforce Change Password Select Yes to ensure the user changes the device password at a regular frequency.
    Password Change frequency If Enforce change password is set to Yes, enter the interval, in days, at which the user is required to change the device password.
    Unique passwords before reuse permitted The VMP Server stores a list of the most recently used passwords for a device. A password cannot be reused if it is one of the N most recent passwords used, where N is the value of this option.
    Maximum failed attempts before device wipe Enter the number of times a password can be incorrectly entered before all system sensitive information is wiped from the device.
    Tip: When configuring password options, remember to consider the speed at which your users must view and respond to critical communications. An auto-lock setting that is too short will impair the user's ability to quickly respond to messages and communications. A password that requires too many characters may also be inhibiting, depending on the environment.
Note: If you change the Enforce App PIN setting to ON, device users will not be able to set a PIN if they registered by email or using a registration key and do not have either a valid VMP Server username and password or a valid Active Directory username and password.