I'm testing a BYOD configuration in Intune that requires iOS devices to use a six-digit PIN, along with other security settings. After applying the policy, I noticed that my Apple Watch also requires a PIN. It appears the watch inherits the passcode requirement from the paired iPhone, and I haven't found a separate setting to exclude the watch. Has anyone dealt with this before or found a practical workaround? I'm considering removing the enforced PIN requirement because another policy already requires biometric authentication.
4 Answers
You can enable the Apple Watch option to unlock it automatically when the iPhone is unlocked. That greatly reduces how often the watch asks for its PIN, although it still needs a PIN during initial pairing and whenever you’re away from the phone, such as during a workout.
If the goal is mainly to protect company data inside managed apps, consider using mobile application management instead of fully managing the personal device. A MAM approach may avoid applying device-wide passcode restrictions, depending on your organization’s requirements and licensing.
One workaround is to stop enforcing the passcode through device management, remove the requirement from the watch, and then set a passcode manually on the iPhone. That leaves the phone protected without having the management policy force the same requirement onto the watch, but it also means the passcode is no longer being enforced by the management system.
This is expected behavior with Apple’s device-management model. A passcode requirement applied to the iPhone is passed on to the paired Apple Watch, and there doesn’t appear to be an MDM option to exempt the watch. Enforcing a more restrictive or alphanumeric passcode can also make the watch difficult to unlock without the phone nearby.

I hadn’t noticed that setting, and it does reduce most of the prompts. It doesn’t eliminate the initial requirement or the prompts when the watch is separated from the phone, though.