Overview
Activation Lock is an Apple anti-theft feature that prevents an iPhone, iPad, or Mac from being reactivated without authorization, even after the device is erased. On supported organization-owned devices, Swif can report Activation Lock information, store an available bypass code, and attempt to clear a manageable Activation Lock.
Activation Lock is different from a device passcode, FileVault recovery key, MDM profile password, or remote lock command. These credentials cannot be used in place of an Activation Lock bypass code.
Before you begin
The available recovery options depend on:
Whether Activation Lock is organization-linked or user-linked.
Whether the device was registered with Apple Business Manager before Activation Lock was enabled.
Whether Find My was enabled before the device enrolled in Swif.
Whether Swif has the bypass code associated with the active lock.
The device model, operating-system version, supervision state, and enrollment method.
For Mac, Activation Lock requires Apple silicon or the Apple T2 Security Chip and macOS Catalina 10.15 or later. Apple also imposes security-policy requirements on eligible Macs. See Activation Lock for Mac for Apple’s current requirements.
Types of Activation Lock
Apple supports two Activation Lock methods for managed devices. They use different management workflows and bypass codes.
Type | How it is enabled | Recovery options |
Organization-linked Activation Lock | The device management service enables Activation Lock through Apple’s servers. | The organization-generated bypass code, a supported server-side removal request, or Apple Business Manager when eligible. |
User-linked Activation Lock | A user signs in with a personal Apple Account and enables Find My. | The user’s Apple Account credentials, Apple Business Manager when eligible, or Apple Support with proof of purchase. |
If both methods are attempted, Apple states that the first successful Activation Lock event takes precedence.
Organization-linked Activation Lock
With organization-linked Activation Lock, the device management service—not the user—contacts Apple’s activation servers to enable the lock. The management service creates and stores a unique, device-specific bypass code that can later be used to clear Activation Lock.
Swif’s Activation Lock management and bypass-code functionality is designed for this organization-linked workflow.
Organization-linked Activation Lock requires the device to be associated with Apple Business Manager or Apple School Manager. Because the organization controls the bypass code, removing the lock does not depend on the employee’s personal Apple Account.
User-linked Activation Lock
User-linked Activation Lock is associated with the personal Apple Account used to enable Find My.
On supervised devices, user-linked Activation Lock is disallowed by default. Apple provides an MDM workflow that can retrieve and store a device-generated bypass code before allowing the user to enable Activation Lock. Swif does not currently support enabling user-linked Activation Lock through this workflow.
However, if a user enabled Find My before enrolling an eligible Mac in Swif, the associated user-linked Activation Lock can remain enabled after the Mac enrolls and becomes supervised. Enrollment in Swif does not automatically remove or replace the existing Activation Lock.
Apple notes that this can occur on a Mac with macOS 11 or later when a previously unmanaged Mac enrolls through Device Enrollment and becomes supervised. In this situation, Swif cannot use MDM commands to turn off the pre-existing user-linked Activation Lock, and macOS cannot disallow it retroactively. The user must turn off Find My using the Apple Account associated with the lock.
Therefore, if a supervised Mac enrolled in Swif has a user-linked Activation Lock, the lock was most likely enabled before the Mac completed enrollment and became supervised. Swif’s organization-linked bypass code is not associated with that personal Apple Account and cannot clear the pre-existing user-linked lock.
To remove the lock, use one of the following options:
Ask the Apple Account owner to turn off Find My or remove the Mac from their account through iCloud Find Devices.
Turn off Activation Lock through Apple Business Manager if the device was registered with the organization before Activation Lock was enabled and has not been released.
Contact Apple Support with valid proof-of-purchase documentation if the other recovery methods are unavailable.
For more information, see Apple’s Activation Lock deployment documentation.
View Activation Lock information in Swif
To review Activation Lock information for an Apple device:
In the Swif Console, go to Device Management > Devices.
Select the device.
Open the Security tab.
Locate the Activation Lock section.
This section can display:
Activation Lock: The Activation Lock state reported for the device.
Manageable: Whether Swif has the management information required to attempt an Activation Lock action.
Bypass code: The device-specific bypass code stored by Swif. Select View only when you need to use it.
Clear: Sends a supported Apple management request to remove Activation Lock.
Treat an Activation Lock bypass code as a sensitive administrative credential. Do not share it with the device user or include it in screenshots, support tickets, email messages, or chat conversations.
Clear Activation Lock from Swif
When the Clear action is available:
Confirm that you selected the correct device.
Select Clear next to Activation Lock.
Wait for the action to complete.
Refresh the device record.
Before reassigning or disposing of the device, confirm that Setup Assistant or macOS Recovery no longer requests the previous owner’s credentials.
Clearing Activation Lock succeeds only when Apple accepts the request and Swif has the bypass code associated with the active organization-linked lock.
A displayed bypass code or Manageable: Yes does not guarantee that every Activation Lock can be removed. For example:
The active lock may be user-linked.
The lock may have been enabled before Swif enrollment.
The lock may have been enabled by a previous MDM service.
Swif’s stored code may not correspond to the currently active lock.
Whenever possible, clear Activation Lock while the device remains enrolled, online, and in your organization’s possession. Complete this step before:
Removing the MDM profile.
Migrating the device to another MDM provider.
Releasing the device from Apple Business Manager.
Erasing, reassigning, selling, or disposing of the device.
Use a Swif bypass code directly on the device
If remote clearing is unavailable but Swif has the bypass code corresponding to the organization-linked lock, you may be able to enter it directly on the device.
iPhone or iPad
At the Activation Lock screen:
Leave the Apple Account username field blank.
Enter the MDM bypass code in the password field.
Follow the on-screen instructions to continue activation.
Mac
Start the Mac in macOS Recovery.
Select Recovery Assistant from the menu bar.
Select Activate with MDM key.
Enter the bypass code stored in Swif.
The bypass code must correspond to the currently active Activation Lock. Swif cannot create a replacement or universal code that Apple’s activation servers will accept.
Turn off Activation Lock in Apple Business Manager
Apple Business Manager can turn off both organization-linked and user-linked Activation Lock when:
The device was registered with the organization before Activation Lock was enabled.
The device has not been released from the organization.
The administrator has a role with permission to manage devices.
The device does not need to remain assigned to an MDM service.
To turn off Activation Lock:
Sign in to Apple Business Manager.
Go to Devices > Inventory.
Search for and select the device.
Under Details, confirm that Activation Lock is enabled.
Select More > Turn Off Activation Lock.
Review the warning and confirm the action.
An erased device may temporarily continue to display Activation Lock as enabled in Apple Business Manager. After the action completes, Setup Assistant should allow the device to be activated without the previous user’s credentials.
See Turn off Activation Lock in Apple Business Manager for Apple’s current instructions.
If the device is linked to a former employee’s Apple Account
Use the following recovery options in order:
Determine the lock type. If the lock is organization-linked and Swif has the corresponding bypass code, try the Clear action in Swif.
Check Apple Business Manager. If the device was registered with the organization before Activation Lock was enabled and has not been released, an authorized administrator may be able to turn off the lock.
Ask the former employee to remove the device from Find My. The employee can sign in to iCloud Find Devices, select the device, erase it if necessary, and select Remove This Device. The employee does not need to share their Apple Account password with the organization.
Contact Apple Support. If the other methods are unavailable, Apple may review an Activation Lock support request with valid proof-of-purchase documentation.
If the employee enabled Find My before the Mac became supervised or enrolled in Swif, the user-linked Activation Lock can remain enabled after enrollment. Swif’s organization-linked bypass code will not remove that pre-existing user-linked lock.
This is an Apple security boundary, not a Swif installation or device-wipe issue. Erasing the Mac does not remove Activation Lock.
Why a bypass code may be rejected
A stored bypass code can fail for several reasons:
The active lock is user-linked, but the stored code is for organization-linked Activation Lock.
Activation Lock was already enabled before the device enrolled in Swif.
The lock was enabled or managed by a previous MDM service.
Another Activation Lock event succeeded first and took precedence.
The device generated a new bypass code after an erase or setup process.
Activation Lock information was not preserved during an MDM migration.
The device was added to Apple Business Manager after Activation Lock was enabled.
The device was released from Apple Business Manager.
The Mac does not meet Apple’s hardware, operating-system, or security requirements.
The time at which Swif collected a bypass code does not, by itself, prove whether the code is valid. The important question is whether Apple associates that code with the currently active Activation Lock.
Recommended deployment practices
Add organization-owned devices to Apple Business Manager before distributing them.
Use Automated Device Enrollment so devices are supervised and managed during initial setup.
Use organization-linked Activation Lock for devices managed by Swif.
Verify that Find My is off before enrolling a previously unmanaged Mac in Swif.
Do not release a device from Apple Business Manager until Activation Lock has been verified as off.
Ask users to disable Find My and sign out of their personal Apple Account before offboarding, repair, reassignment, sale, or MDM migration.
Clear Activation Lock before erasing a device or removing its MDM enrollment.
During an MDM migration, securely preserve applicable bypass codes or clear Activation Lock before moving the device.
Test your Activation Lock workflow on a small number of devices before deploying it throughout the organization.
Key points
Apple supports organization-linked and user-linked Activation Lock.
The two methods use different management workflows and bypass codes.
Swif currently supports the organization-linked Activation Lock workflow.
Swif does not currently enable user-linked Activation Lock through Apple’s MDM workflow.
User-linked Activation Lock enabled before Swif enrollment can remain enabled after the Mac enrolls and becomes supervised.
Swif enrollment does not retroactively remove a pre-existing user-linked Activation Lock.
Swif’s organization-linked bypass code cannot clear a pre-existing user-linked lock.
Apple Business Manager may remove either lock type when its eligibility requirements are met.
Erasing a device does not remove Activation Lock.
If no management recovery method applies, the Apple Account owner or Apple Support must remove the lock.

