> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# recoveryOS protection

> Configure recoveryOS settings on macOS devices to prevent unauthorized access to recovery tools.

## Platform compatibility

| macOS | Windows | Linux | iOS / iPadOS | Android |
| ----- | ------- | ----- | ------------ | ------- |
| ✅     |         |       |              |         |

## How to set it up

<Steps>
  <Step title="Select targeting">
    No additional configuration is required. Choose which devices to apply the control to: all macOS devices, specific device groups, or a custom target.
  </Step>
</Steps>

## Modify or remove the control

Disable the control from the profile settings. Disabling stops enforcement but does not remove existing configurations from devices.

## How it works

Primo delivers a macOS security configuration payload via MDM that applies restrictions to the recoveryOS environment. These settings are enforced at a firmware level on Apple Silicon Macs and at the security policy level on Intel Macs.

<Info>
  On Apple Silicon Macs, recoveryOS restrictions are integrated with the Secure Enclave. Full enforcement requires that the device is enrolled in MDM with the appropriate supervision level.
</Info>
