macOS Recovery Lock in Microsoft Intune: A Step-by-Step Guide
Password-protect macOS recovery mode, then view and rotate the passcode from the Intune admin center.
What it is and why it matters
Recovery Lock protects the macOS recovery environment (recoveryOS) with a password managed by Intune. It prevents users from booting a corporate Mac into recovery mode, reinstalling macOS or bypassing remote management — while IT can retrieve or rotate the password from the admin center.
The password can rotate automatically on a schedule or on demand, and it protects the Startup Options screen.
What you’ll need
- macOS devices enrolled in Intune (Apple silicon)
- The Intune administrator role, or a custom role with Remote tasks > Rotate macOS recovery lock password and View macOS recovery lock password
Step 1 — Create the Recovery Lock policy
- Go to
Devices > macOS > Configurationand select Create > New policy. - Profile type: Settings catalog.
- Search for Recovery lock password and add the category.
- Set Enable Recovery Lock Password = Enabled and Recovery Lock Password Rotation Schedule = 1 to 12 months.
- Assign to your macOS device group and select Create.
Step 2 — Verify the policy applied
Open the policy and check Device status — target Macs should show Succeeded after their next check-in.
Step 3 — View the Recovery Lock passcode
- Go to
Devices > All devicesand select the macOS device. - Select Passwords and keys, then View Recovery Lock Passcode.
If no Recovery Lock policy is configured for the device, the option is greyed out.
Step 4 — Rotate the passcode on demand
- Select the macOS device in
Devices > All devices. - Select Rotate recovery lock passcode and confirm.
- The new passcode applies the next time the device checks in; until then the previous passcode remains valid.
Verify it works
- The policy shows Succeeded on the device.
- The passcode is visible under Passwords and keys.
- Entering recovery mode on the Mac now prompts for the Recovery Lock password.
Troubleshooting notes
The existing passcode stays in effect until the device checks in and receives the new one.
The device isn’t assigned a Recovery Lock policy, or your role lacks the View/Rotate macOS recovery lock password permissions.
Use the policy schedule for routine rotation; use the on-demand action when a user forgets the passcode or a device changes hands.