Skip to main content
Activation Lock prevents unauthorized use of an Apple device after a factory reset. For company-owned devices enrolled in MDM, Primo can escrow the bypass code automatically — so IT admins can unlock a device after a wipe without needing the employee’s Apple ID.

OS Support

macOSWindowsLinuxiOS / iPadOSAndroid

Rules for escrowing bypass codes

For a bypass code to be successfully escrowed, all of the following conditions must be met:
  1. The device must be supervised via MDM — unsupervised devices cannot escrow bypass codes.
  2. The device must be enrolled before Activation Lock is enabled — if a user activates Find My before MDM enrollment, the bypass code will not be available.
  3. The device must be a company-owned device — personally-owned (BYOD) devices are not eligible for bypass code escrow.
  4. The MDM profile must be installed at the system level — user-approved enrollment (without DEP/ABM) may not reliably escrow bypass codes.
If a device is enrolled in MDM after the user has already signed in with an Apple ID and enabled Find My, the bypass code will not be escrowed. The only recovery option is the user’s Apple ID credentials.

Check bypass code availability

  1. Go to Devices > All Devices.
  2. Open the relevant device record.
  3. Scroll to the Compliance section.
  4. Check the iCloud Lock status:
    • Enabled — the bypass code is available and escrowed.
    • Missing bypass code — no code was backed up; the original Apple ID is required.
Run a regular audit of devices showing Missing bypass code to identify machines that may be unrecoverable after a wipe. Prioritize re-enrolling these devices via ABM if possible.

On macOS

Retrieve the bypass code from the device record, then:
  • macOS Catalina (10.15) and later: on the Activation Lock screen, click the question mark next to the Apple ID field, select Bypass activation lock, and enter the code.
  • macOS Mojave (10.14) and earlier: enter the bypass code directly in the password field on the Activation Lock screen.
The bypass code is case-sensitive and is generally single-use per device.

On iOS / iPadOS

For iOS and iPadOS devices, retrieve the bypass code from the device record and enter it on the Activation Lock screen when prompted during device setup after a wipe. The bypass code is case-sensitive and is generally single-use per device.