Device Action: Set and Rotate Admin Password
SimpleMDM can remotely change the password of a Mac's automatically-created local administrator account. This is useful for periodically rotating admin credentials for security purposes, or for setting a specific password when needed for support or troubleshooting.
Requirements
This action is available on Macs running macOS 10.11 or later that were set up with an administrator account automatically created during Automated Enrollment (Apple's Setup Assistant flow that creates a local admin account for MDM management). If the Mac does not have this automatically-created admin account, the Set and Rotate Admin Password options will not be available.
Where to find it
Both options appear on the Mac's Device Details page, next to the Admin Password field:
- A pencil icon ("set password") opens a form to specify an exact new password.
- A circular arrow icon ("rotate password") generates and sends a new random password with no further input required.
Setting a specific password
- On the Mac's Device Details page, click the pencil ("set password") icon next to Admin Password.
- Enter the new password in the field provided. The password must meet your account's password policy.
- Click "Save" to send the new password to the device.
Rotating to a random password
- On the Mac's Device Details page, click the circular arrow ("rotate password") icon next to Admin Password.
- Confirm the prompt. A new random password is generated and sent to the device — no admin input is required.
Rotating and setting a password both use the same underlying command, so a rotation simply replaces the manual password entry step with an automatically generated one.
Viewing the current password
The current admin password is hidden by default on the Device Details page. Admins with permission to view admin passwords can reveal or copy it from the Admin Password field. SimpleMDM retains a history of the 10 most recently set passwords for the device.
The password is only updated in SimpleMDM once the Mac confirms it received and applied the change. If the device is offline, the command is queued and delivered the next time it checks in — the previous password remains in effect until the new one is confirmed.
Audit logs
Setting a password, rotating a password, and viewing or copying a stored password are each recorded separately in the account's audit log.
Notes
- This action only manages the automatically-created local admin account from Automated Enrollment — it does not change the password of other local user accounts on the Mac.
- Viewing or copying a stored admin password requires a separate permission from setting or rotating one, so accounts can be configured to allow rotation without allowing password visibility.