Skip to main content

Configure Iru (Kandji) - Screen Lock

When using Iru (formerly Kandji), Vanta will look for screen lock settings enforced via a Passcode Library Item assigned to a Blueprint. This applies to both macOS and Windows devices managed by Iru.

Create a passcode library item

  • In Iru, navigate to Library and select Add Library Item.

  • Search for and select Passcode.

  • Click the Add and configure button.

  • Enter a title for the Library Item (i.e. Screen Lock Policy).

  • Under Install on, select the platform(s) you want to target: MacOS, Windows, or both.

  • Assign the Library Item to the relevant blueprints.

Configure screen lock settings

MacOS

  • Configure the following settings within the Passcode Library Item:

    • Start screen saver after: Enable this setting and set it to 15 minutes or less.

    • Require after sleep/screen saver/lock: Enable this setting to require a password after the screen saver activates.

Both settings must be configured in the same Passcode Library Item.

Windows

Configure the following setting within the Passcode Library Item:

  • Configure max inactivity time: Enable this setting and set it to 15 minutes or less. This forces the device to the PIN/password lock screen after the defined period of inactivity.

Assign to a Blueprint

Once the Passcode Library Item is configured, confirm it is assigned to a Blueprint that is applied to your target devices. Click Save. Vanta will detect screen lock compliance once the Library Item is active on the device.

⚠️ Note: The previous Screen Saver Profile method is no longer supported for macOS devices in Iru, as Apple has removed support for profile-based screen saver configuration. The Passcode Library Item is the required method for enforcing screen lock on both macOS and Windows devices going forward.