Security FAQ: Transitioning from Patterns to Passwords

Created by Matt Rock, Modified on Mon, 29 Dec, 2025 at 2:40 PM by Matt Rock

To help the team understand the necessity of this shift, we’ve compiled answers to the most common questions regarding endpoint security at RACTSOL.

Q: Why is RACTSOL phasing out patterns?


A: Swipe patterns are significantly more vulnerable to "shoulder surfing" (being watched from a distance) and "smudge attacks" (oily residue left on the screen that reveals the unlock path). Alphanumeric passwords provide a much higher level of entropy, making it mathematically harder for an adversary to guess or bypass your work profile.



Q: Does this change apply to my personal profile on the same device?


A: No. This policy update specifically targets the Work Profile container. While we strongly recommend using a password for your entire device, RACTSOL only enforces these standards on the profile containing company, DOD, and NATO information.


Q: Can I use biometric authentication (Fingerprint/Face ID) instead?


A: Yes, biometrics are generally permitted as a secondary "convenience" unlock. However, a strong password or PIN must remain the primary "Work Challenge" that the system reverts to after a restart or failed biometric attempt.

Q: What happens if I don't update my lock type by the deadline?


A: Once the policy is fully enforced, your work profile will be marked as "Non-Compliant". This may result in an automatic lock-out from work applications (email, Teams, internal drives) until a compliant password is set4.

How to Construct a Compliant Password

A strong password is your first line of defense in protecting NATO and RACTSOL intellectual property. Use the "Passphrase" method to make your password easy to remember but hard to crack.


  • Avoid Sequences: Do not use "1234," "abcd," or "password".
  • Use the Rule of Three: Combine three random, unrelated words (e.g., Blue-Bridge-Coffee!).
  • Update Responsibility: If you suspect your password has been compromised, you must report the incident to the Security Officer immediately.

     


Q: I’m having trouble setting the password. What should I do?
A: If your device settings do not allow you to select "Password," it may be due to an outdated OS version or a sync error with our management software. Please submit a ticket at:

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article