# Set Firmware/Recovery lock password on macOS devices

The **Set Firmware/Recovery Lock Password** remote action allows IT administrators to secure macOS devices at the hardware level, preventing unauthorized users from booting from external media, reinstalling the OS, or accessing recovery tools.

**What are Firmware and Recovery Locks?**
-----------------------------------------

These passwords serve as the primary line of defense against physical tampering. By locking the boot process, organizations ensure that corporate data remains protected even if the device is physically stolen.

- **Firmware Password (Intel):** Protects Intel-based Macs by restricting startup key combinations and non-default startup disks.
- **Recovery Lock (Apple Silicon):** By replacing the firmware password on the Macs, this feature restricts access to recoveryOS and is exclusively manageable via UEM.
- **Data Integrity:** Prevents intruders from erasing the device or bypassing security mechanisms via external bootable drives.

**Prerequisites and Compatibility**
-----------------------------------

Before deploying these locks, ensure the target hardware meets the following version and processor requirements:

FeatureSupported OSProcessor Type**Firmware Password**macOS 10.13 or laterIntel-based Mac**Recovery Lock**macOS 11.5 or laterApple silicon (M-series)**Management**Enrolled in **Hexnode UEM**All supported models**Step-by-Step Guide: Configuring Hardware Locks**
--------------------------------------------------

Administrators can apply a uniform password across multiple devices or set unique credentials for individual units.

1. Log in to the **Hexnode UEM portal**.
2. Navigate to **Manage > Devices**.
3. Select the target device(s) or click a specific device name.
4. Navigate to **Actions > Security > Set Firmware/Recovery Lock Password**.
5. Configure the setup options: 
    - **Current password:** Enter the existing password if one is set; otherwise, leave blank.
    - **New password:** Specify the new hardware-level password.
    - **Confirm new password:** Re-enter to ensure accuracy.
    - **Option ROMs (Intel Only):** Check to allow or uncheck to block external hardware firmware from running at startup.
6. Click **Confirm**.

[![Set Firmware/Recovery lock password on macOS devices with Hexnode](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/10/Set-FirmwareRecovery-lock-password-on-macOS-devices-scaled.png "Set Firmware/Recovery lock password on macOS devices")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/10/Set-FirmwareRecovery-lock-password-on-macOS-devices-scaled.png)

**How to View and Verify Escrowed Passwords**
---------------------------------------------

Hexnode automatically escrows (safely stores) these passwords in the portal for emergency recovery.

- **To View:** Navigate to **Manage > Devices > [Device Name] > Device Info > Security Info**. Look for the **Firmware/Recovery password** field.
- **To Verify (Intel):** If the password was changed locally on the device, use the **Verify Firmware Password** remote action to check for a match with the portal’s records.

[![Set Firmware/Recovery lock password on macOS devices with Hexnode](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/10/Firmware-or-Recovery-password-escrowed-to-portal.png "Firmware or Recovery password escrowed to portal")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/10/Firmware-or-Recovery-password-escrowed-to-portal.png)

**Troubleshooting Guides**
--------------------------

ProblemPotential CauseResolutionAction returns an errorRapid-fire requests.Requests can only be made once every 30 seconds. Wait for the interval to pass before retrying.Password not taking effectDevice requires a reboot (Intel).For Intel-based Macs, a device restart is mandatory for the new firmware password to initialize.Recovery Lock missing after unenrollmentAutomatic system behavior.On Apple silicon devices, the system automatically removes the recovery password when the device is disenrolled.Action greyed outUnsupported OS version.Verify the device is running at least macOS 10.13 (Intel) or 11.5 (Apple silicon).**Frequently Asked Questions (FAQs)**
-------------------------------------

### **What is the difference between Firmware Password and Recovery Lock?**

A Firmware Password (Intel) can be set manually or via UEM and restricts boot-key combinations. A Recovery Lock (Apple silicon) can only be configured via a UEM like Hexnode and specifically protects recoveryOS.

### **What are Option ROMs?**

Option ROMs are firmware programs on external peripherals (like network adapters or GPUs). On Intel Macs, disabling them improves security by blocking potentially malicious external firmware from loading during the boot sequence.

### **How to reset a forgotten password**

Yes, provided the action was executed via Hexnode. The password is encrypted and stored in the **Security Info** section of the device in the portal.

### **Does setting this password affect the user’s login password?**

No. This is a hardware-level lock. It only appears when someone tries to enter Recovery Mode or boot from an external drive; it does not replace the standard macOS user login.