Disable Activation Lock for Apple Devices Using Microsoft Intune

Disable Activation Lock in Microsoft Intune

You don’t realize how important Activation Lock is until it stops you from reusing a device.

An employee returns their corporate iPhone after leaving the organization. The device is wiped and ready for its next user—or at least it should be. Instead, you’re prompted for the previous user’s Apple Account credentials because Activation Lock is still enabled.

This is exactly what Activation Lock is designed to do. Apple’s built-in security feature protects iPhones and iPads from unauthorized access by preventing anyone from erasing or reactivating a device without the associated Apple Account credentials. It’s excellent protection against theft, but during employee offboarding or device refreshes, it can quickly become an operational challenge.

Until the lock is removed, the device can’t be activated or reassigned. Many IT admins run into this situation during device recovery and redeployment.

How does Disable Activation Lock in Microsoft Intune help?

For supervised iPhones and iPads enrolled through Apple Automated Device Enrollment (ADE), Microsoft Intune provides a simple way to remove this roadblock.

Administrators can either disable Activation Lock remotely or retrieve the device’s Activation Lock bypass code, eliminating the need to contact the previous user for their Apple Account credentials.

In most cases, it’s as simple as selecting the device in Intune, running the Disable Activation Lock action, and preparing the device for its next user.

This lets organizations keep the security benefits of Apple’s theft protection without letting that same protection interfere with day-to-day device management.

Before relying on this capability, keep these requirements in mind:

  • Activation Lock must be enabled through an Intune Settings Catalog policy while the device is supervised. This isn’t enabled by default.
  • If someone signs back into Find My after Activation Lock is removed, the lock is enabled again. For that reason, it’s recommended to perform this action only when the device is physically in your possession.

Also, this capability is available only for supervised iOS/iPadOS devices enrolled through Apple Automated Device Enrollment (ADE). Personally enrolled and unsupervised devices aren’t supported.

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Powered by Amail.