Skip to main content

Managing Apple Activation Lock with Swif

Overview

Activation Lock is an Apple anti-theft feature that prevents an iPhone, iPad, or Mac from being reactivated without authorization, even after the device is erased.

Swif can retrieve and securely store the device-generated Activation Lock bypass code reported by an eligible enrolled device. An administrator can view this code in Swif and use it directly on the device if the code corresponds to the active user-linked Activation Lock.

Swif does not currently:

  • Enable user-linked Activation Lock after retrieving the bypass code.

  • Enable or disable organization-linked Activation Lock through Apple’s server-side API.

  • Remotely remove Activation Lock from Apple’s activation servers.

Important: The Clear button in Swif does not remove Activation Lock. It sends Apple’s ClearActivationLockBypassCode command, which clears the device-held bypass code. Do not use Clear as an Activation Lock recovery action.

Activation Lock is different from a device passcode, FileVault recovery key, Recovery Lock password, MDM profile, or remote lock command. Those credentials cannot be used in place of an Activation Lock credential.

Requirements and limitations

The available recovery options depend on:

  • Whether Activation Lock was enabled before or after the device enrolled in Swif.

  • Whether the device was added to Apple Business Manager before Activation Lock was enabled.

  • Whether the device remains assigned to your organization in Apple Business Manager.

  • Whether the bypass code stored in Swif corresponds to the active lock.

  • The device model, operating-system version, supervision state, and enrollment method.

For Mac, Activation Lock management requires Apple silicon or the Apple T2 Security Chip. Review Activation Lock for Mac for Apple’s current device and security requirements.


Understand the two types of Activation Lock

Apple supports two Activation Lock workflows for organization-owned devices.

Type

How it is enabled

Swif support

User-linked Activation Lock

A user signs in with a personal Apple Account and enables Find My. On a supervised device, the management service must allow Activation Lock.

Swif stores a device-generated bypass code when Apple makes one available, but Swif does not currently send the command that allows user-linked Activation Lock after enrollment.

Organization-linked Activation Lock

A management service linked to Apple Business Manager or Apple School Manager enables the lock directly through Apple’s activation servers.

Swif does not currently enable or disable organization-linked Activation Lock through Apple’s API.

These workflows use different management mechanisms and bypass codes. A device-generated bypass code stored by Swif is not an organization-linked bypass code.

User-linked Activation Lock

User-linked Activation Lock is associated with the personal Apple Account used to enable Find My.

Activation Lock is disallowed by default when an eligible device becomes supervised. Apple allows a management service to retrieve and store a device-generated bypass code and then explicitly allow the user to enable Activation Lock.

Swif currently retrieves and stores a device-generated bypass code when the device reports one, but it does not send the command that allows user-linked Activation Lock after enrollment. Therefore, if a Swif-enrolled supervised device already has user-linked Activation Lock enabled, the lock was generally enabled before Swif enrolled and supervised the device.

This situation can occur on Mac with macOS 11 or later when a previously unmanaged Mac enrolls through Device Enrollment. Apple explains that Activation Lock can already be active when the Mac enrolls and becomes supervised. In that case, the new management service cannot turn off the pre-existing lock.

A bypass code collected during or after Swif enrollment does not automatically correspond to a user-linked lock that was already active. If the active lock predates Swif management, Apple may reject the code stored by Swif because it is not the bypass code associated with that lock.

For iPhone and iPad, Apple makes the device-generated bypass code available for up to 15 days after the device first becomes supervised, or until a management service retrieves and then explicitly clears the device-held code. If no management service retrieves the code during that period, it cannot be recovered later.

Organization-linked Activation Lock

Organization-linked Activation Lock requires Apple Business Manager or Apple School Manager. A supporting management service creates its own bypass code and communicates directly with Apple’s activation servers to turn the lock on or off.

Swif does not currently implement this organization-linked workflow. Swif does not create an organization-linked bypass code or use Apple’s server-side API to enable or remove organization-linked Activation Lock.

If an eligible device belongs to your organization in Apple Business Manager, an authorized Apple Business Manager administrator may still be able to turn off Activation Lock there. This Apple Business Manager recovery method is separate from Swif.

View Activation Lock information in Swif

To review a device:

  1. In the Swif Console, go to Device Management > Devices.

  2. Select the Apple device.

  3. Open the Security tab.

  4. Locate the Activation Lock section.

The section can display:

  • Activation Lock: The Activation Lock state reported for the device.

  • Manageable: Management information reported for the device. This value does not guarantee that the code stored by Swif can remove the active lock.

  • Bypass Code: The device-generated bypass code retrieved and stored by Swif. Select View only when you need to use it.

  • Clear: Sends Apple’s command to clear the bypass code held by the device. It does not turn off Activation Lock.

Insert the supplied screenshot here. Caption: Activation Lock status and bypass-code information under Device Details > Security.

Treat an Activation Lock bypass code as a sensitive administrative credential. Do not share it with the device user or expose it in screenshots, support tickets, email, or chat messages.

What the Clear button does

The Clear button sends Apple’s ClearActivationLockBypassCode MDM command to the enrolled device. This command removes the device-held copy of its bypass code.

The command does not:

  • Turn off Find My.

  • Sign the user out of their Apple Account.

  • Remove user-linked Activation Lock.

  • Remove organization-linked Activation Lock.

  • Send a request to Apple’s activation servers to unlock the device.

  • Confirm that the bypass code stored in Swif matches the active lock.

After the device successfully clears its bypass code, that code cannot be retrieved from the device again. Do not select Clear while troubleshooting Activation Lock or before an MDM migration unless you fully understand the effect and have preserved any required recovery information.

The Clear action should be used only when an administrator intentionally wants to remove the bypass code from the device. It should never be described or used as a way to clear Activation Lock.


Use the bypass code directly on the device

If the device is at the Activation Lock screen and the bypass code stored by Swif corresponds to the active user-linked lock, Apple supports entering the code directly on eligible devices.

iPhone or iPad

At the Activation Lock screen:

  1. Leave the Apple Account field blank.

  2. Enter the bypass code from Swif in the password field.

Mac

  1. Start the Mac in macOS Recovery.

  2. In the menu bar, select Recovery Assistant.

  3. Select Activate with MDM key.

  4. Enter the bypass code stored in Swif.

Apple will reject the code if it does not correspond to the active lock. Swif cannot generate a replacement or universal bypass code.

Turn off Activation Lock in Apple Business Manager

Apple Business Manager can turn off user-linked or organization-linked Activation Lock for an organization-owned device when:

  • The device was added to the organization before Activation Lock was enabled.

  • The device has not been released from the organization.

  • The administrator has permission to manage devices and turn off Activation Lock.

The device does not need to remain assigned to an MDM server.

To turn off Activation Lock:

  1. Sign in to Apple Business Manager with an account that has the required permission.

  2. Go to Devices.

  3. Search for and select the device.

  4. Confirm that Activation Lock is enabled.

  5. Select More > Turn Off Activation Lock.

  6. Review the warning and confirm the action.

This process communicates with Apple’s activation servers and is different from selecting Clear in Swif.

See Turn off Activation Lock in Apple Business Manager for Apple’s current instructions.

If the device is linked to a former employee’s Apple Account

Use the following recovery order:

  1. Check when Activation Lock was enabled. If it was enabled before the device enrolled in Swif, the bypass code collected by Swif during enrollment may not correspond to the existing lock.

  2. Check Apple Business Manager. If the device was added to your organization before Activation Lock was enabled and has not been released, an authorized administrator may be able to turn off the lock.

  3. Ask the former employee to remove the device from Find My. The employee can sign in to Find Devices on iCloud.com, select the device, and choose Remove This Device. They do not need to give the organization their Apple Account password.

  4. Try the Swif bypass code directly on the device only if you have reason to believe it corresponds to the active user-linked lock.

  5. Contact Apple Support. If the other methods are unavailable, Apple may require valid proof-of-purchase documentation before reviewing an Activation Lock support request.

Do not select Clear in Swif during this process. It does not remove the former employee’s Activation Lock and clears the bypass code held by the device.

Why the bypass code may be rejected

Apple may reject the code stored in Swif when:

  • Activation Lock was enabled before the device enrolled in Swif.

  • The stored device-generated code does not correspond to the active lock.

  • The active lock is organization-linked and requires the organization-linked recovery workflow.

  • A different Activation Lock event took precedence.

  • The code changed during an erase, setup, or MDM migration.

  • The eligible iPhone or iPad code was not retrieved during Apple’s availability window.

  • The Mac does not meet Apple’s hardware, operating-system, supervision, or security requirements.

The time at which Swif retrieved a code does not by itself prove that the code is valid for the active lock. The important question is whether Apple associates that exact code with the Activation Lock currently protecting the device.

Recommended practices

  • Add organization-owned devices to Apple Business Manager before distributing them.

  • Use Automated Device Enrollment so devices are managed and supervised during initial setup.

  • Do not release a device from Apple Business Manager until Activation Lock is off and the device is ready to leave the organization.

  • Ask users not to enable Find My with a personal Apple Account on organization-owned devices unless your organization has an approved recovery workflow.

  • Require users to turn off Find My and sign out of their personal Apple Account before offboarding, reassignment, repair, sale, or MDM migration.

  • Verify that Activation Lock is off before erasing or unenrolling a device.

  • Do not use the Swif Clear button as an unlock action.

  • Before clearing a device-held bypass code or migrating MDM services, securely preserve any recovery information your organization is authorized to retain.

  • Test the complete offboarding and recovery workflow on a small number of devices.

Key points

  • Swif stores a device-generated Activation Lock bypass code when Apple makes one available.

  • Swif does not currently enable user-linked Activation Lock after enrollment.

  • Swif does not currently support Apple’s organization-linked Activation Lock workflow.

  • The bypass code stored by Swif may not unlock Activation Lock that existed before Swif enrollment.

  • The Clear button clears the bypass code held by the device; it does not clear Activation Lock.

  • Apple Business Manager may be able to turn off Activation Lock when the device was added to the organization before the lock was enabled and has not been released.

  • If no organizational recovery method applies, the Apple Account owner or Apple Support must remove the lock.

Apple references

Did this answer your question?