Description
Recovery lock codes can be set in the PreStage for Jamf Enrolled MacBooks. Recovery Lock prevents access to the Recovery OS unless a user enters a 6 digit code assigned during the PreStage. In certain cases device code may become unknown. Most commonly this is due to a sync issue with the commands in the database. This type of behavior is noted in Product Issues such as PI122875 and PI111426.
If the PRK is unknown and the device is locked out Admins will need the Recovery Key to authenticate to the Recovery Volume. Because the Recovery Lock Password is unknown Admins will not be able to enter Recovery Mode to reinstall the OS.
In general, this process is extraordinarily hands on and requires significant investment of time from the Admin. If other remedies are available to get the admin into the MacBook, they should be pursued before proceeding.
Customers affected by issues like this have reported that Apple informed them that they would need to do an out of warranty logic board replacement. That appears to be incorrect and customers should be able to put the device back into service using the following workflow.
Workflow to identify eligible device:
Must be Apple Silicon.
Must have a recovery lock set.
Restoring Your Device
This workflow was tested and confirmed on a MacBook Air M2 with a Apple Configurator on a MacBook Air M2 on March 17th, 2025
Workflow to resolve affected device:
Connect the affected MacBook's DFU USB-C port to another MacBook. If you do not know which USB-C port is the DFU port, you can find it listed here.
Boot the MacBook into DFU ( you have trouble, you can use DFU Blaster, it's free for 14 days)
Utilize the Restore option in Apple Configurator or the Finder Window on the Mac that is connected to the DFU Booted MacBook. Documentation for this process can be found here. Apple calls out using a revive prior to a restore. Based on the documentation, revive does not appear to remove the Recovery Lock and would still require authentication to the Recovery OS or Operating System OS to initiate an Erase All Content and Settings.
Once restore is complete, the device will boot to Setup Assistant. As long as the device is enrolled in Apple Business Manager, the Admin should be able to proceed from here as normal. If the device is not enrolled in MDM and has an Apple Account associated with it, the Admin would need to have the device removed from the user's Apple Account or authenticate to that account.