Swif lets admins reset a user's password on a managed device from the Swif console. Use it when a user forgets their password or is locked out, or during a security incident or offboarding.
Important: The device must be online. Swif sends the password reset as a command, so the device must be turned on, connected to the internet, and checking in with Swif. If a Mac is offline or stuck at the FileVault screen, see Reset a FileVault Password When a Mac Is Offline.
Supported platforms
Platform | Password reset from Swif |
macOS | ✅ Supported, using the Swif Admin account |
Windows | ✅ Supported |
Linux | ✅ Supported |
Android | ✅ Supported. Learn more |
iOS and iPadOS | ❌ Not supported. The device may need to be erased. |
Before you begin
Make sure that:
the device is enrolled and active in Swif
the device is online. Check Last Connected on the device page; a recent time means it's checking in.
you have admin permissions in Swif
the user account exists on the device
If the device is offline
The reset command can't reach an offline device. Choose the option that fits:
Situation | What to do |
The Mac is offline, or stuck at the FileVault screen | Follow Reset a FileVault Password When a Mac Is Offline. It covers the Swif Admin account, the user's Apple Account, and the FileVault recovery key. |
The Mac account is locked after too many failed attempts | Clear the lock with Lock Reset. See Resetting Account Lock After Failed Login Attempts on macOS. |
Any other device | Ask the user to connect the device to the internet, wait for it to check in with Swif, then reset the password. |
How password reset works on macOS
Swif doesn't bypass macOS security. Instead:
Swif creates and manages a Swif Admin account on each Mac.
Swif uses that account to authorize the password change, following macOS's normal security rules.
The user's old password stops working immediately.
This keeps every reset auditable, works with FileVault, and doesn't need unsupported system changes.
For security, macOS may ask for admin authentication when password resets happen frequently.
FileVault password sync
On a Mac with FileVault on, resetting a password outside the user's active macOS session can leave the FileVault password and the macOS login password temporarily out of sync. When that happens:
the old password may still be needed at the FileVault screen
the new password may work only after macOS fully starts up
This often happens after:
password resets by an admin
password changes in an identity provider
Active Directory or Platform SSO password updates
To reduce sync problems, have users change their password while logged in to macOS, or use Swif's password reset.
For troubleshooting, see FileVault Password Synchronization on macOS.
Reset a password
Step 1: Open the device
Go to Device Management > Devices.
Select the user's device.
Open the Accounts tab.
Step 2: Choose the user account
Find the user whose password you want to reset.
Click the ⋯ menu.
Select Reset Password.
Step 3: Complete the reset
The Reset Password dialog walks you through three steps:
[Screenshot: Reset Password dialog]
Authentication (macOS)
Set new password
Enter the new password. Your password policy is checked before the reset is sent (see below).
Share password
Share the new password with the user through a secure channel.
Ask the user to change it after they log in.
Click Proceed, then Save Changes.
What happens after the reset
The old password stops working immediately.
The user can log in with the new password.
The action is recorded in Audit Trail.
The device's compliance status updates automatically.
On a Mac with FileVault on, the user may need to log in once with the new password to fully unlock the disk. No data is lost.
Password policy checks
If a password policy is assigned to the device, Swif checks the new password against it before sending the reset. This stops admins from setting passwords that are too weak or break your compliance rules.
No password policy assigned: Swif sends the reset without checking.
Password policy assigned: the new password must meet every rule, or Swif rejects the reset.
What Swif checks
Depending on your policy, Swif checks:
minimum password length
complexity, such as a mix of uppercase and lowercase letters, numbers, and symbols
password history, so users can't reuse recent passwords
expiration or maximum age rules, where they apply at reset time
lockout-related rules, where they apply
any other password rules in the policy
What you see in Swif
If the new password doesn't meet the policy:
Swif rejects the reset and doesn't send it to the device.
The API returns a 400 error with the code
PASSWORD_POLICY_VALIDATION.The Commands tab shows a policy validation failure, not a device error.
Example message:
Password does not meet policy: minimum entropy is 48 bits (current: 23.3).
Use more unique characters and/or greater length.
Make the password longer or more varied, then try again.
If the new password meets the policy:
Swif sends the reset to the device.
The password changes once the device runs the command.
The action is recorded in Audit Trail.
Turn on policy checks
To make Swif check passwords on reset, assign a password policy to the device or to a group that includes it. For example, on Windows, assign a Windows password policy with your minimum length, complexity, and other rules.
Security best practices
Verify the user's identity before resetting their password.
Use temporary passwords when you can.
Ask users to change their password after they log in.
Review resets in Audit Trail.
If you need to troubleshoot on the device, use temporary admin access.
Troubleshooting
The Reset Password option isn't available
The device is probably offline. Check Last Connected on the device page. If the device isn't checking in, see If the device is offline.
The reset command doesn't complete
The device may have gone offline after you sent the reset. Check the command's status on the device's Commands tab. If the user needs access right away on a Mac, see Reset a FileVault Password When a Mac Is Offline.
Swif rejects the new password
The password doesn't meet the device's password policy. Read the error message, change the password, and try again.
The user still can't log in
Make sure you reset the correct account.
On a Mac, check FileVault status. The old password may still be needed at the FileVault screen until the passwords sync.
Try the reset again after the device checks in.
The Mac account is locked after failed attempts
If the account is locked after too many failed attempts, clear the lock with Lock Reset. See Resetting Account Lock After Failed Login Attempts on macOS.
