# Bypass Activation Lock using Hexnode UEM

**Activation Lock** is an Apple security feature that prevents unauthorized access to lost or stolen devices by requiring the previous user’s **Apple Account** credentials after a factory reset.

**Why Bypass Activation Lock in Enterprise?**
---------------------------------------------

In corporate environments, Activation Lock becomes a hurdle when an employee leaves the organization without signing out of their personal iCloud account. Hexnode UEM allows IT admins to bypass this lock to repurpose or redeploy company-owned assets.

![bypass activation lock with Apple Account and password on locked devices](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/04/bypass-activation-lock-with-Apple-ID-and-password-on-devices.jpeg)

**Prerequisites and Support**
-----------------------------

For the bypass methods to function, the devices must be currently managed by **Hexnode UEM** and meet the following criteria:

RequirementDetails**iCloud State**The device must be signed in to iCloud with **Find My** enabled.**iOS / iPadOS**Must be **Supervised** and running **iOS 7.1+**.**macOS**Running **macOS 10.15+** with **Apple T2 security chip** or enrolled in **ABM/ASM**.**ADE Enrollment****Bypass Codes** are supported only on **Automated Device Enrollment (ADE)** devices.**Methods to Clear Activation Lock**
------------------------------------

### **Method 1: Remote Clear via Hexnode Console**

This method sends a direct command to the Apple servers to remove the lock associated with the managed device.

1. Log in to the **Hexnode UEM portal**.
2. Navigate to the **Manage** tab and select the target device.
3. Click **Actions > Security > Clear activation lock**.
4. **Confirm** the action to send the command.

### **Method 2: Manual Bypass with Bypass Code**

If the device is already at the “Activation Lock” setup screen, you can retrieve a unique alphanumeric code from Hexnode to unlock it.

1. Navigate to the **Manage** tab and select the target device.
2. Go to the **Device Info** tab.
3. Locate the **Activation Lock** section.
4. Click the **eye icon** to reveal the **Activation Lock Bypass Code**.

#### **Verify Activation Lock Bypass Codes from the Hexnode console**

- **Multiple Bypass Codes Display:** If Hexnode cannot determine which Activation Lock type is active on the device, but tracking logs are available for both lock types, the portal displays both the **Managed Activation Lock Bypass Code** and the **User Activation Lock Bypass Code**.
- **Bypass Code “N/A” Status:** An **N/A** value appears in the user-based field due to specific scenarios, such as when more than 15 days have passed since the device was first supervised or when a previous MDM vendor wiped the code before Hexnode UEM enrollment. Meanwhile, **N/A** appears in the organization-based field to confirm that lock type is inactive. This explicitly indicates that the active lock is user-based, preventing admins from searching for a non-existent code.
- **Portal Status Discrepancies:** The **Activation Lock** status may be inaccurate if it was enabled on the device before Hexnode UEM enrollment. To avoid confusion regarding its true state, verify the status directly inside your **Apple Business** or **Apple School Manager** console.

#### **How to Apply the Bypass Code on the Device**

Device TypeEntry Instructions**iOS / iPadOS**Enter the code in the **Password** field; leave **Apple Account** blank.**iOS (Alternative)**If the account field is required, enter the **Bypass Code** in the **Apple Account** field.**macOS**Click **Recovery Assistant** in the top menu bar > select **Activate with MDM key…** > enter the code.**How to Re-activate Activation Lock**
--------------------------------------

To restore protection, the user must manually re-enable **Find My** services on the device:

- **iOS 13+:** Go to **Settings > [Your Name] > Find My > Turn On Find My [Device]**.
- **iOS 12 or earlier:** Go to **Settings > [Your Name] > iCloud > Turn On Find My**.
- **macOS:** Click the **Apple Icon > System Preferences > Apple Account > iCloud > Enable Find My Mac**.

**Troubleshooting Guides**
--------------------------

ProblemResolution**“Clear Activation Lock” action fails**Ensure the device is **Online**. If the device is wiped and cannot reach Wi-Fi, it cannot receive the remote “Clear” command. Use **Method 2 (Bypass Code)** instead.**Bypass Code is not visible in portal**Verify the device was enrolled via **ADE (formerly DEP)**. Standard manual enrollments do not consistently generate or store bypass codes in the UEM.**Bypass Code rejected on device**Ensure the code is entered exactly as shown (case-sensitive). For macOS, verify you have selected **Activate with MDM key** in the Recovery Assistant.**Frequently Asked Questions (FAQs)**
-------------------------------------

#### **Why is Activation Lock an issue for enterprise environments?**

It blocks IT admins from reusing company-owned devices if they are linked to an employee’s personal Apple Account. Without the credentials, the device remains an unusable “brick”.

#### **Does bypassing Activation Lock remove the device from iCloud?**

No. Bypassing allows you to gain access to the device hardware, but it does not remove the device from the previous user’s list of “Find My” devices in their iCloud account.

#### **Can Activation Lock be cleared if the device is offline?**

No. The device requires an internet connection to communicate with Apple’s activation servers to verify the “Clear” command or the “Bypass Code”.