Skip to main content

Apple User Authorization Policy

Overview

The Apple User Authorization Policy controls two user account changes on managed Apple devices:

  • Passcode and password changes: whether users can add, change, or remove the device passcode on iPhone and iPad, or change their password on a Mac.

  • Local user creation: whether users can create new user accounts in System Settings on a Mac.

Important: On iPhone and iPad, turning off passcode modification also stops users from adding a passcode. Apple's restriction prevents adding, changing, or removing the passcode. If a device has no passcode when the policy applies, the user can't set one until you turn the setting back on. Make sure devices already have a passcode, or apply the Apple Password Policy first.


Supported platforms and requirements

Item

Details

Platforms

macOS, iOS, iPadOS

Minimum OS

macOS 10.13, iOS 9.0, iPadOS 9.0 (Allow Local User Creation requires macOS 14)

Device ownership

Company-owned devices; BYOD Macs

Supervision

Required on iPhone and iPad. Not required on Mac.

Shared iPad

Not supported. Shared iPad ignores these settings.

Apple User Enrollment

Not supported. Apple doesn't allow these restrictions on User Enrollment.

BYOD Macs. This policy works on Macs enrolled as BYOD with the Swif installer. On those Macs, the policy profile can't be updated or removed remotely after it installs. See BYOD Limitation (Apple, Windows).


Settings reference

Setting

What it does when turned off

Default

Platforms and minimum OS

Supervision

Allow Passcode Modification

iPhone and iPad: users can't add, change, or remove the device passcode.

Mac: users can't change their password.

On

macOS 10.13, iOS/iPadOS 9.0

Required on iOS/iPadOS

Allow Local User Creation

Users can't create new user accounts in System Settings.

On

macOS 14

Not required

Both settings on means the device isn't restricted. Check both before you save the policy.

What these settings don't cover

  • Password resets by another administrator. On a Mac, an administrator account can still reset another user's password. Swif can't block this with this policy.

  • Account creation outside System Settings. Apple limits Allow Local User Creation to creating users in System Settings. It doesn't say the setting affects other methods, such as command-line tools or accounts created during enrollment or by Platform SSO. Test any method your users might use.

  • Existing accounts. Turning off Allow Local User Creation doesn't remove accounts that already exist.


Using this policy with other Swif policies

  • Apple Password Policy: If that policy makes passwords expire, users need to be able to change their password. Don't turn off Allow Passcode Modification on the same devices unless users have another way to change it, such as a Swif-managed reset. Test the combination before rollout.

  • Apple Login Window Policy: Its Disallow user to change password setting also affects password changes on Macs. Use one policy for this, not both.

  • Apple Platform SSO Policy: With Platform SSO, the identity provider manages the password. Turning off Allow Passcode Modification stops users from changing the local password separately.


Before you start

  1. Decide how users will change passwords. If you block local changes, give users another way, such as your identity provider or a Swif-managed reset.

  2. Check that iPhones and iPads are supervised. Allow Passcode Modification doesn't apply to unsupervised devices.

  3. Check that iPhones and iPads already have a passcode. Users can't add one after the policy applies.

  4. Check macOS versions. Macs before macOS 14 ignore Allow Local User Creation.

  5. Make sure an administrator account exists on each Mac before you block local user creation.


Create the policy

  1. In Swif, go to Device Management > Policies > New Policy.

  2. Select Apple User Authorization Policy.

  3. Enter a clear name, such as Mac – Block Local Accounts.

  4. Set Allow Passcode Modification.

  5. Set Allow Local User Creation (applies to Macs only).

  6. Check both settings again, then save the policy.

  7. Assign it to a device group.

  8. Test on a few devices before a wider rollout.


Example configurations

Example 1: Company Macs with Platform SSO

Users sign in with your identity provider, which manages their passwords.

Setting

Value

Allow Passcode Modification

Off

Allow Local User Creation

Off

Users can't change the local password or create extra accounts. They change their password through the identity provider.

Example 2: Company Macs where users manage their own password

You want to stop extra accounts but let users change their password.

Setting

Value

Allow Passcode Modification

On

Allow Local User Creation

Off

Example 3: Supervised shared iPhones for frontline staff

The team uses one known passcode, and you don't want anyone to change or remove it.

Setting

Value

Allow Passcode Modification

Off

Allow Local User Creation

On (has no effect on iPhone)

Set the passcode before you apply the policy. Users can't add one afterward.


Verify the policy

Mac

  1. Open System Settings > General > Device Management and open the Swif profile. Confirm that it includes the restrictions.

  2. If Allow Local User Creation is off, go to System Settings > Users & Groups and confirm that you can't add a user.

  3. If Allow Passcode Modification is off, try to change the password in System Settings > Users & Groups. The change shouldn't be allowed.

iPhone or iPad

  1. Go to Settings > General > VPN & Device Management, open the Swif profile, and confirm that it lists the restriction.

  2. Open Settings > Face ID & Passcode (or Touch ID & Passcode). The options to change or turn off the passcode shouldn't be available.

In Swif, open the device and confirm that the policy shows as applied.


Troubleshooting

An iPhone or iPad still lets users change the passcode

The device probably isn't supervised. Also check that it isn't a Shared iPad, which ignores this setting.

A user can't set a passcode on an iPhone or iPad

This is expected when Allow Passcode Modification is off. Turn it on, let the user set a passcode, then turn it off again.

Users can't change an expiring password

Allow Passcode Modification is off while a password policy requires changes. Turn it on, or provide another way to change passwords.

Macs still allow adding users

Check that the Mac runs macOS 14 or later.

A password was changed even though the policy blocks it

Another administrator account may have reset it. This policy doesn't prevent resets by administrators.

Nothing applies on a personal iPhone, iPad, or Mac enrolled with Apple User Enrollment

Apple doesn't allow these restrictions on User Enrollment.


Related resources

Swif

Apple

Did this answer your question?