> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Activation Lock bypass code escrow

> Rules for ensuring Activation Lock bypass codes are escrowed via MDM so devices can be recovered after a wipe or reassignment.

Activation Lock prevents unauthorized use of an Apple device after a factory reset. For company-owned devices enrolled in MDM, Primo escrows the bypass code automatically. You can then unlock a device after a wipe without the employee's Apple ID.

<Note>
  On Mac, Activation Lock only applies to devices with Apple Silicon or the Apple T2 Security Chip. Older Intel Macs without a T2 chip are not affected ([Apple Deployment Guide](https://support.apple.com/guide/deployment/depf4ab94ef1/web)).
</Note>

## OS support

| macOS | Windows | Linux | iOS / iPadOS | Android |
| ----- | ------- | ----- | ------------ | ------- |
| ✅     |         |       | ✅            |         |

## The two types of Activation Lock

Apple distinguishes two ways Activation Lock can be enabled on an organization-owned device ([Apple Deployment Guide](https://support.apple.com/guide/deployment/depf4ab94ef1/web)):

* **Organization-linked** — requires the device to be in Apple Business Manager (ABM) or Apple School Manager. The MDM contacts Apple's servers directly to lock and unlock the device, using its own server-generated bypass code. Nothing depends on the user, on Find My, or on the state of the device.
* **User-linked** — the user locks the device to their personal Apple Account by enabling **Find My**. This is the type covered by the escrow rules and scenarios below.

<Note>
  If both types are attempted on the same device, the first Activation Lock event that enables the feature takes precedence.
</Note>

## Rules for escrowing bypass codes

All of the following conditions must apply for Primo to escrow a bypass code:

1. **The device must be supervised via MDM** — unsupervised devices cannot escrow bypass codes.
2. **You must enroll the device before Activation Lock is enabled** — if a user activates Find My before MDM enrollment, Primo cannot retrieve the bypass code.
3. **The device must be company-owned** — personally-owned (BYOD) devices are not eligible for bypass code escrow.
4. **The MDM profile must install at the system level** — user-approved enrollment (without DEP/ABM) does not reliably escrow bypass codes.

<Warning>
  If you enroll a device in MDM after the user has already signed in with an Apple ID and enabled Find My, **Primo cannot escrow the bypass code**. The only recovery option is the user's Apple ID credentials.
</Warning>

## Scenarios and caveats

Whether a bypass code is usable depends on the device's supervision state and the order in which device management and Activation Lock were enabled. The same **iCloud Lock** field in the dashboard can show a value that is reliable in one scenario and a false positive in another.

### Key terms

* **Supervision** — per [Apple](https://support.apple.com/en-gb/guide/deployment/dep1d89f0bff/web), supervision "denotes that the device is owned by the organisation, which provides additional control over its configuration and restrictions." A device is supervised when enrolled through Automated Device Enrollment (ADE), zero-touch deployment, or Apple Business Manager (ABM). On macOS 11 and later, Macs enrolled via account-driven or profile-based Device Enrollment are also supervised. Standard user enrollment does not grant supervision.
* **Activation Lock** — Apple's protection that ties a device to an Apple ID after a wipe. It triggers when a user enables **Find My** on the device.
* **Bypass code** — a device-based code that removes Activation Lock without the user's Apple ID. The code only exists if Primo escrowed it.
* **Escrow** — device management stores the bypass code at the moment Activation Lock activates. Escrow is not retroactive.

### The three scenarios

On macOS 11 and later, most enrolled Macs are supervised (Scenario 1), even without zero-touch. Scenarios 2 and 3 apply to devices that remain unsupervised — for example, older macOS versions or pure user enrollment.

| Scenario                            | Supervision                  | Order of events                     | Bypass code    |
| ----------------------------------- | ---------------------------- | ----------------------------------- | -------------- |
| **1. Supervised**                   | Supervised (ZTD / ADE / ABM) | Enrolled via zero-touch             | ✅ Reliable     |
| **2. Unsupervised, enrolled first** | Unsupervised                 | MDM enrolled → then Find My enabled | ✅ Escrowed     |
| **3. Unsupervised, Find My first**  | Unsupervised                 | Find My enabled → then MDM enrolled | ❌ Not escrowed |

**Scenario 1 — Supervised device.** Activation Lock is not a blocker. Device management sends an `ActivationLockBypassCodeCommand` directly to the device, regardless of when the user enabled Find My. The bypass code is reliable.

**Scenario 2 — Unsupervised, MDM enrolled before Find My.** You enrolled the device manually (unsupervised), but device management was already in place when the user enabled Find My. Primo escrowed the bypass code at that moment, and you can use it.

**Scenario 3 — Unsupervised, Find My before MDM.** The user enabled Find My before enrolling in device management. Activation Lock was already active, so Primo could not escrow a bypass code. Any code shown in the dashboard is a **false positive** — entering it on the Activation Lock screen returns `Your Apple Account or password is incorrect`. The only recovery option is the user's Apple ID credentials.

<Note>
  Apple provides no way to confirm whether an escrowed bypass code is a valid device-based code. On unsupervised devices, users can also toggle Find My off and on without re-escrowing a new code. Treat the **iCloud Lock** value on unsupervised devices as unverified until you confirm the device's enrollment history.
</Note>

## Check bypass code availability

<Steps>
  <Step title="Go to Devices > All Devices" />

  <Step title="Open the relevant device record" />

  <Step title="Scroll to the Compliance section" />

  <Step title="Check the iCloud Lock status">
    * ✅ *Enabled* — the bypass code is available and escrowed.
    * ❌ *Missing bypass code* — Primo did not back up a code, and you need the original Apple ID.
  </Step>
</Steps>

<Info>
  Audit devices showing **Missing bypass code** regularly to identify devices that may be unrecoverable after a wipe. Re-enroll these devices via ABM when possible.
</Info>

## On macOS

Retrieve the bypass code from the device record, then start the Mac and wait for the Activation Lock screen. Click **Recovery Assistant** in the menu bar and select **Activate with MDM key**, then enter the bypass code ([Apple Deployment Guide](https://support.apple.com/guide/deployment/depf4ab94ef1/web)).

The bypass code is case-sensitive and single-use per device.

## On iOS / iPadOS

For iOS and iPadOS devices, retrieve the bypass code from the device record. On the Activation Lock screen during device setup after a wipe, enter the bypass code in the **password** field and leave the username field empty ([Apple Deployment Guide](https://support.apple.com/guide/deployment/depf4ab94ef1/web)).

The bypass code is case-sensitive and single-use per device.

<Warning>
  On iPhone and iPad, you can only retrieve the device-generated bypass code during the **15 days** following first supervision of the device (or until an MDM explicitly fetches and clears it). If Primo did not escrow the code within that window, it is gone for good.
</Warning>

## Recover a Mac stuck on the Activate Mac screen

If a Mac was wiped while Activation Lock was still active and no valid bypass code exists (Scenario 3), it stays locked on the **Activate Mac** screen. Do not keep retrying the bypass code — it returns `Your Apple Account or password is incorrect` because the code was never escrowed.

Work through these options in order.

### Option 1 — Disable Activation Lock from Apple Business Manager

If the Mac was added to ABM **before** Activation Lock was enabled, and has not been released from the organization, a user with device management privileges can disable Activation Lock directly from ABM — for both organization-linked and user-linked locks. The device does not need to be assigned to an MDM server ([Apple Deployment Guide](https://support.apple.com/guide/deployment/depf4ab94ef1/web)).

<Note>
  For an **organization-linked** lock that the MDM fails to remove, there is one more fallback: on the Activation Lock screen, sign in with the ABM account that created the MDM server token linking Primo to ABM.
</Note>

### Option 2 — Ask the former user

If the previous user is reachable, they can release the lock themselves:

* by signing in with their Apple ID directly on the Activation Lock screen, or
* by removing the device from their account: go to [icloud.com/find](https://www.icloud.com/find), select the device, then choose **Remove This Device** ([Apple Support](https://support.apple.com/108934)). This also works from any of their other Apple devices.

This is usually the fastest path — try it before contacting Apple.

### Option 3 — Apple Support with proof of ownership

If the former user is unreachable, Apple can remove Activation Lock when the organization proves it owns the device. Gather these before contacting Apple:

* the original purchase invoice in the company's name, showing the device serial number
* the device serial number (visible on the Activation Lock screen or on the chassis)
* company details and the requester's identity

Submit the request through [Apple's Activation Lock support page](https://al-support.apple.com/), or through your AppleCare for Business or Enterprise agreement if you have one ([Apple Support: How to remove Activation Lock](https://support.apple.com/108934)). Verification typically takes several days. Apple rejects requests with an incomplete invoice or a missing serial number.

<Info>
  This situation is almost always avoidable: sign the user out of iCloud before wiping any unsupervised Mac. See [Wiping devices](/mdm/guides/wiping-devices).
</Info>

***

## Related articles

* [Wiping devices](/mdm/guides/wiping-devices)
* [Locking devices](/mdm/guides/locking-devices)
* [Migrate using Apple Business](/mdm/rollout/migrating-macs-using-abm)
* [Apple Deployment Guide — Activation Lock for Apple devices](https://support.apple.com/guide/deployment/depf4ab94ef1/web)
* [Apple Support — How to remove Activation Lock](https://support.apple.com/108934)
