Skip to main content
Activation Lock prevents unauthorized use of an Apple device after a factory reset. For company-owned devices enrolled in MDM, Primo escrows the bypass code automatically. You can then unlock a device after a wipe without the employee’s Apple ID.

OS support

macOSWindowsLinuxiOS / iPadOSAndroid

Rules for escrowing bypass codes

All of the following conditions must apply for Primo to escrow a bypass code:
  1. The device must be supervised via MDM — unsupervised devices cannot escrow bypass codes.
  2. You must enroll the device before Activation Lock is enabled — if a user activates Find My before MDM enrollment, Primo cannot retrieve the bypass code.
  3. The device must be company-owned — personally-owned (BYOD) devices are not eligible for bypass code escrow.
  4. The MDM profile must install at the system level — user-approved enrollment (without DEP/ABM) does not reliably escrow bypass codes.
If you enroll a device in MDM after the user has already signed in with an Apple ID and enabled Find My, Primo cannot escrow the bypass code. The only recovery option is the user’s Apple ID credentials.

Scenarios and caveats

Whether a bypass code is usable depends on the device’s supervision state and the order in which device management and Activation Lock were enabled. The same iCloud Lock field in the dashboard can show a value that is reliable in one scenario and a false positive in another.

Key terms

  • Supervision — per Apple, supervision “denotes that the device is owned by the organisation, which provides additional control over its configuration and restrictions.” A device is supervised when enrolled through Automated Device Enrollment (ADE), zero-touch deployment, or Apple Business Manager (ABM). On macOS 11 and later, Macs enrolled via account-driven or profile-based Device Enrollment are also supervised. Standard user enrollment does not grant supervision.
  • Activation Lock — Apple’s protection that ties a device to an Apple ID after a wipe. It triggers when a user enables Find My on the device.
  • Bypass code — a device-based code that removes Activation Lock without the user’s Apple ID. The code only exists if Primo escrowed it.
  • Escrow — device management stores the bypass code at the moment Activation Lock activates. Escrow is not retroactive.

The three scenarios

On macOS 11 and later, most enrolled Macs are supervised (Scenario 1), even without zero-touch. Scenarios 2 and 3 apply to devices that remain unsupervised — for example, older macOS versions or pure user enrollment.
ScenarioSupervisionOrder of eventsBypass code
1. SupervisedSupervised (ZTD / ADE / ABM)Enrolled via zero-touch✅ Reliable
2. Unsupervised, enrolled firstUnsupervisedMDM enrolled → then Find My enabled✅ Escrowed
3. Unsupervised, Find My firstUnsupervisedFind My enabled → then MDM enrolled❌ Not escrowed
Scenario 1 — Supervised device. Activation Lock is not a blocker. Device management sends an ActivationLockBypassCodeCommand directly to the device, regardless of when the user enabled Find My. The bypass code is reliable. Scenario 2 — Unsupervised, MDM enrolled before Find My. You enrolled the device manually (unsupervised), but device management was already in place when the user enabled Find My. Primo escrowed the bypass code at that moment, and you can use it. Scenario 3 — Unsupervised, Find My before MDM. The user enabled Find My before enrolling in device management. Activation Lock was already active, so Primo could not escrow a bypass code. Any code shown in the dashboard is a false positive — entering it on the Activation Lock screen returns Your Apple Account or password is incorrect. The only recovery option is the user’s Apple ID credentials.
Apple provides no way to confirm whether an escrowed bypass code is a valid device-based code. On unsupervised devices, users can also toggle Find My off and on without re-escrowing a new code. Treat the iCloud Lock value on unsupervised devices as unverified until you confirm the device’s enrollment history.

Check bypass code availability

1

Go to Devices > All Devices

2

Open the relevant device record

3

Scroll to the Compliance section

4

Check the iCloud Lock status

  • Enabled — the bypass code is available and escrowed.
  • Missing bypass code — Primo did not back up a code, and you need the original Apple ID.
Audit devices showing Missing bypass code regularly to identify devices that may be unrecoverable after a wipe. Re-enroll these devices via ABM when possible.

On macOS

Retrieve the bypass code from the device record, then:
  • macOS Catalina (10.15) and later: on the Activation Lock screen, click the question mark next to the Apple ID field, select Bypass activation lock, and enter the code.
  • macOS Mojave (10.14) and earlier: enter the bypass code directly in the password field on the Activation Lock screen.
The bypass code is case-sensitive and is generally single-use per device.

On iOS / iPadOS

For iOS and iPadOS devices, retrieve the bypass code from the device record and enter it on the Activation Lock screen when prompted during device setup after a wipe. The bypass code is case-sensitive and is generally single-use per device.