Device Action: Clear Recovery Lock Password
Recovery Lock is a security feature on Apple Silicon Macs that requires a password before someone can start up from a different disk, enter Recovery Mode, or use certain diagnostic and recovery tools. The Clear Recovery Lock Password device action removes the currently set Recovery Lock password from a Mac, disabling this restriction.
Requirements
- The device must be a Mac running macOS 11.5 or later, enrolled via Automated/Device Enrollment.
- A Recovery Lock password must currently be set and verified on the device. If no Recovery Lock password is on file, this action will not be available.
- The device cannot have a Recovery Lock Password configuration profile currently assigned. If one is assigned, it must be unassigned from the device (and any groups it belongs to) before the password can be cleared.
How to clear a Recovery Lock password
- Navigate to the Mac's Device Details page.
- Click "Actions", then select "Clear Recovery Lock Password".
- Confirm the prompt. A command is sent to the device to remove the Recovery Lock password.
If a Recovery Lock Password configuration is still assigned to the device, the request will be rejected with a message asking you to unassign the configuration first. Once the configuration is unassigned, retry the Clear action.
Notes
- Clearing the password only removes it from the device — it does not disable Recovery Lock itself, which is enabled and configured via the Recovery Lock Password profile type.
- Rotating to a new random or specified Recovery Lock password is a separate action from clearing, and is only available on Apple Silicon Macs.
- Once cleared, the device will no longer require a password to enter Recovery Mode or start up from another disk until a new Recovery Lock password is set.
Eric McCann
Was this article helpful?