Overview
The Apple User Authorization Policy controls two user account changes on managed Apple devices:
Passcode and password changes: whether users can add, change, or remove the device passcode on iPhone and iPad, or change their password on a Mac.
Local user creation: whether users can create new user accounts in System Settings on a Mac.
Important: On iPhone and iPad, turning off passcode modification also stops users from adding a passcode. Apple's restriction prevents adding, changing, or removing the passcode. If a device has no passcode when the policy applies, the user can't set one until you turn the setting back on. Make sure devices already have a passcode, or apply the Apple Password Policy first.
Supported platforms and requirements
Item | Details |
Platforms | macOS, iOS, iPadOS |
Minimum OS | macOS 10.13, iOS 9.0, iPadOS 9.0 (Allow Local User Creation requires macOS 14) |
Device ownership | Company-owned devices; BYOD Macs |
Supervision | Required on iPhone and iPad. Not required on Mac. |
Shared iPad | Not supported. Shared iPad ignores these settings. |
Apple User Enrollment | Not supported. Apple doesn't allow these restrictions on User Enrollment. |
BYOD Macs. This policy works on Macs enrolled as BYOD with the Swif installer. On those Macs, the policy profile can't be updated or removed remotely after it installs. See BYOD Limitation (Apple, Windows).
Settings reference
Setting | What it does when turned off | Default | Platforms and minimum OS | Supervision |
Allow Passcode Modification | iPhone and iPad: users can't add, change, or remove the device passcode.
Mac: users can't change their password. | On | macOS 10.13, iOS/iPadOS 9.0 | Required on iOS/iPadOS |
Allow Local User Creation | Users can't create new user accounts in System Settings. | On | macOS 14 | Not required |
Both settings on means the device isn't restricted. Check both before you save the policy.
What these settings don't cover
Password resets by another administrator. On a Mac, an administrator account can still reset another user's password. Swif can't block this with this policy.
Account creation outside System Settings. Apple limits Allow Local User Creation to creating users in System Settings. It doesn't say the setting affects other methods, such as command-line tools or accounts created during enrollment or by Platform SSO. Test any method your users might use.
Existing accounts. Turning off Allow Local User Creation doesn't remove accounts that already exist.
Using this policy with other Swif policies
Apple Password Policy: If that policy makes passwords expire, users need to be able to change their password. Don't turn off Allow Passcode Modification on the same devices unless users have another way to change it, such as a Swif-managed reset. Test the combination before rollout.
Apple Login Window Policy: Its Disallow user to change password setting also affects password changes on Macs. Use one policy for this, not both.
Apple Platform SSO Policy: With Platform SSO, the identity provider manages the password. Turning off Allow Passcode Modification stops users from changing the local password separately.
Before you start
Decide how users will change passwords. If you block local changes, give users another way, such as your identity provider or a Swif-managed reset.
Check that iPhones and iPads are supervised. Allow Passcode Modification doesn't apply to unsupervised devices.
Check that iPhones and iPads already have a passcode. Users can't add one after the policy applies.
Check macOS versions. Macs before macOS 14 ignore Allow Local User Creation.
Make sure an administrator account exists on each Mac before you block local user creation.
Create the policy
In Swif, go to Device Management > Policies > New Policy.
Select Apple User Authorization Policy.
Enter a clear name, such as
Mac – Block Local Accounts.Set Allow Passcode Modification.
Set Allow Local User Creation (applies to Macs only).
Check both settings again, then save the policy.
Assign it to a device group.
Test on a few devices before a wider rollout.
Example configurations
Example 1: Company Macs with Platform SSO
Users sign in with your identity provider, which manages their passwords.
Setting | Value |
Allow Passcode Modification | Off |
Allow Local User Creation | Off |
Users can't change the local password or create extra accounts. They change their password through the identity provider.
Example 2: Company Macs where users manage their own password
You want to stop extra accounts but let users change their password.
Setting | Value |
Allow Passcode Modification | On |
Allow Local User Creation | Off |
Example 3: Supervised shared iPhones for frontline staff
The team uses one known passcode, and you don't want anyone to change or remove it.
Setting | Value |
Allow Passcode Modification | Off |
Allow Local User Creation | On (has no effect on iPhone) |
Set the passcode before you apply the policy. Users can't add one afterward.
Verify the policy
Mac
Open System Settings > General > Device Management and open the Swif profile. Confirm that it includes the restrictions.
If Allow Local User Creation is off, go to System Settings > Users & Groups and confirm that you can't add a user.
If Allow Passcode Modification is off, try to change the password in System Settings > Users & Groups. The change shouldn't be allowed.
iPhone or iPad
Go to Settings > General > VPN & Device Management, open the Swif profile, and confirm that it lists the restriction.
Open Settings > Face ID & Passcode (or Touch ID & Passcode). The options to change or turn off the passcode shouldn't be available.
In Swif, open the device and confirm that the policy shows as applied.
Troubleshooting
An iPhone or iPad still lets users change the passcode
The device probably isn't supervised. Also check that it isn't a Shared iPad, which ignores this setting.
A user can't set a passcode on an iPhone or iPad
This is expected when Allow Passcode Modification is off. Turn it on, let the user set a passcode, then turn it off again.
Users can't change an expiring password
Allow Passcode Modification is off while a password policy requires changes. Turn it on, or provide another way to change passwords.
Macs still allow adding users
Check that the Mac runs macOS 14 or later.
A password was changed even though the policy blocks it
Another administrator account may have reset it. This policy doesn't prevent resets by administrators.
Nothing applies on a personal iPhone, iPad, or Mac enrolled with Apple User Enrollment
Apple doesn't allow these restrictions on User Enrollment.
Related resources
Swif
Apple