When devices are managed by Swif.ai, a special administrative account called "Swif admin" is created by default. Its visibility and purpose depend on the device's operating system and ownership type.
Swif admin password complexity
The Swif admin password is generated to meet a minimum length of 16 characters. This helps avoid conflicts with stricter tenant password policies (for example, environments that require at least a 16‑character password).
In some workflows (such as device migrations or re-enrollment flows), end users may be prompted to set or update the Swif admin password if the local device password policy requires it. In those cases, the new password must still comply with both the device’s local policy and Swif’s minimum complexity requirements.
macOS
Visibility: The Swif admin account is hidden by default.
Purpose: Facilitates secure remote management and administrative tasks without interfering with the end-user.
Settings: Refer to Managing BYOD Enrollment for macOS in Swif to control the Swif admin behavior. Specifically, setting "Disable device admin user" to enabled to prevent the creation of the Swif admin account.
Capabilities: On macOS devices, the Swif admin user is utilized for certain elevated tasks, such as privileged actions for remote management or troubleshooting.
✔ Create or modify user accounts
✔ Reset or change passwords
✔ Retrieve FileVault Disk Encryption (FDE) recovery keys
✔ Secure Token management for account recovery
✔ Run as Swif admin user for a command
Automatic Recovery of a Disabled Swif Admin Account
If the Swif admin account is disabled, it cannot be used to sign in or perform administrative operations that require the account until recovery completes.
The Swif agent includes an automatic recovery process:
The agent detects that the Swif admin account is disabled or unavailable.
It first attempts to repair and recover the existing account.
If the existing account cannot be recovered, the agent deletes it and creates a new Swif admin account.
The recreated account is configured using the credentials and security requirements managed by Swif.
The recovery process runs automatically while the device is online and communicating with Swif. Recovery may not occur immediately. The exact timing can depend on agent check-in, device connectivity, and the required macOS account operations.
Important: Avoid manually deleting, renaming, enabling, or changing the password of the Swif admin account while recovery is in progress. Manual changes can interfere with the agent’s recovery attempt.
Secure Token Password Prompt
During recovery or recreation, macOS may display a prompt requesting the password of an existing Secure Token-enabled user.
A Secure Token may be required to authorize account recovery, grant the recreated Swif admin account the necessary privileges, or support FileVault-related operations. Apple explains Secure Token behavior in Use secure token, bootstrap token, and volume ownership in deployments.
If the prompt appears:
Confirm that it is a macOS or Swif-initiated prompt associated with the recovery process.
Enter the password for an authorized Secure Token-enabled local user when requested.
Keep the device powered on and connected to the internet.
Allow the Swif agent time to complete recovery.
Verify the Swif admin account’s status in the Swif Admin Dashboard.
The password is requested by macOS to authorize the Secure Token operation. Do not provide the password to Swif Support or send it through email or chat.
The Swif Admin Account Remains Disabled
If recovery does not complete:
Confirm that the Swif agent is running and online.
Confirm that the device appears online in the Swif Admin Dashboard.
Restart the device and allow the agent to check in again.
Check whether a local security policy or another management product is disabling the account.
Look for a pending Secure Token password prompt.
Confirm that an active Secure Token-enabled administrator is available.
Avoid repeatedly modifying the account manually.
Contact Swif Support if the account remains unavailable after the device has checked in.
If Swif recreates the account, there may be a short period during which the original account is unavailable and the replacement account has not yet completed configuration.
Windows
Visibility: The Swif admin user is visible by default, including the domain joined Windows machine. Note, on BYOD Windows, no Swif admin is created. Learn more at BYOD Limitation (Apple, Windows).
Purpose: Allows administrators to perform remote administrative operations.
Linux
Purpose: Provides a secure and non-intrusive way to perform administrative and remote management tasks.
Visibility: The Swif admin account is hidden by default, and can log in to. After a soft wipe, the Swif admin becomes non-hidden and can log in.
Automatic Swif Admin Password Enforcement on Linux Devices
On Linux devices managed by Swif.ai, the Swif Admin (
swifteam) account password is automatically monitored and enforced to match the value stored on the Swif MDM server.Routine Checks:
The Swif agent routinely checks if the local Swif Admin password matches the server’s record.Automatic Reset:
If the password is changed locally (outside of Swif), the agent will automatically reset it to the server’s value. If a password history policy is enforced, a new compliant password will be generated and set both on the device and in the server.No User Alert:
This process is silent—no user notification or UI alert is shown on Linux devices.Reporting:
Any detected password change is reported to the MDM server, allowing administrators to review these events in the Swif Web App.Policy Compliance:
Password resets respect any configured password policies, including history and complexity requirements.
Note:
This behavior ensures that the Swif Admin account remains secure and consistent across all managed Linux devices, with no manual intervention required from end users.Settings: The Swif admin can be managed based on device ownership. For detailed instructions, see Managing the Swif Admin User on Linux (BYOD and Non-BYOD).
Company-Owned vs. BYOD Devices
Company-Owned Devices: Swif admin accounts are created by default to ensure seamless remote administration.
BYOD Devices: Swif admin accounts may be disabled or hidden based on specific enrollment settings, respecting user privacy and device ownership.