How to Reset Apple Firmware Password Macbook Air

How to Reset Apple Firmware Password Macbook Air

MrMacintosh.com - How to remove the firmware password on 2011-2020 Macs + New way for 2018-2020 T2 Macs!
How to remove the firmware password on 2011-2020 Macs + New way for 2018-2020 T2 Macs!

You can now remove the firmware countersign (+ erase all data) on a T2 Mac without Apple Support if y’all forgot it.

In this commodity, I will become over the history of the firmware password on Intel Mac computers. Later on that, I will show you a new mode how to remove the firmware password (and erase your data) on a T2 Mac from 2018-2020.
(Scroll to department half-dozen).

Note: This data is just for 2006-2020 Intel Mac computers. Apple Silicon M1 Mac Devices exercise not have a firmware countersign.

I volition likewise become over my recommendations on how you lot can protect your data at the end of this article.

I will answer the post-obit questions.

  1. What does setting a firmware password on a Mac do?
  2. What are the differences in firmware passwords from the post-obit years – 2006-2010, 2011-2017 & 2018-2020?
  3. How to you fix the firmware password in recovery.
  4. How to Enable & Disable Firmware Password in macOS.
  5. What can you do if you forget the firmware countersign?
  6. How to remove the firmware password with Apple tree Support.
  7. Removing the firmware password on a T2 Mac with Apple Configurator 2.
  8. How long was this new style possible? Does anyone at AppleCare know near this?
  9. What does this hateful for education, modest & large companies, dwelling house users, estimator recyclers, and criminals?
  10. What does Apple think about this?
  11. How can I protect my Data on an Intel and M1 Mac?

1. What does setting a firmware password on a Mac do?

The firmware password was designed to protect your Mac. This mode protects confronting someone who wants to get your data. They can’t kick into target deejay mode or recovery to access your files.

Long story short, if your Mac lands in the wrong easily and you practice Not have the following items enabled below, all your information is at risk!.

  1. Firmware Password
  2. FileVault 2 Encryption
  3. Activation Lock / Find My Mac

A person could access your information via Target disk mode or macOS Recovery, even if they do not know your user password!

When yous set a firmware password, users who don’t take the password tin can’t get-go up from any disk other than the designated startup disk.

https://support.apple tree.com/en-us/HT204455

The Apple article below details different startup modes.

https://support.apple.com/en-gb/HT201255

If y’all enable the firmware password, the post-obit startup items are disabled.

  1. Target Disk Mode
    – (T)
  2. Netboot
    (N) – (Retrieve Netboot?)
  3. Unmarried User Way
    – (Command S)
  4. Verbose Mode
    – (Command 5)
  5. Squirt CD-ROM or DVD
    – (Eject Key)
  6. Safe Mode
    – (Shift Key)
  7. Reset PRAM
    – (Selection-Command-P-R)
  8. Hardware Diagnostics
    – (D)
Read:  How to Update Firmware on Dji Phantom 2 Vision Plus

The post-obit startup options will work, but you will be prompted for the firmware password.

  1. Recovery Mode
    – (Command R)
  2. Internet Recovery
    – (Command Selection R
    or
    Control Option Shift R)

If you have the firmware countersign enabled and you hear someone say “I reset the PRAM” …. NOPE!!!

2. What are the differences in firmware passwords from the following years – (2006-2010), (2011-2017) & (2018-2020)?

  1. (2006-2010) – The firmware countersign could be removed by removing the battery, one stick of ram, and resetting the PRAM iii times.
  2. (2011-2017) Apple inverse this when they soldered the memory to the logic board. The only fashion to remove the firmware password was to contact Apple.
  3. (2018-2020) Apple added the T2 security flake. The chip runs an operating system chosen BridgeOS.
    This OS software can at present be re-installed or updated using a second Mac and Apple tree Configurator two.
    You now need to be an admin user that has a SecureToken to access the Startup Security Utility card to set and remove the firmware password.

3. How practice you prepare the firmware password?

The firmware countersign tin can be prepare in three different ways.

https://support.apple tree.com/en-united states/HT204455

  1. Enable from macOS Recovery.
  1. First up from macOS Recovery.
  2. When the utilities window appears, click Utilities in the carte bar, and then choose Startup Security Utility or Firmware Password Utility.
  3. Click Turn On Firmware Countersign.
  4. Enter a firmware countersign in the fields provided, and so click Set Password.Think this countersign.
  5. Quit the utility, then choose Apple carte > Restart.

2.
Utilize the
firmwarepasswd
binary


sudo firmwarepasswd -setpasswd

3.
Plough on “Discover My” through iCloud, which enables the firmware password & Activation Lock.

four. How to Enable & Disable Firmware Password in macOS?

You can enable and disable the firmware password inside macOS using terminal.app

  • ane.
    sudo firmwarepasswd -setpasswd
    = Set a new countersign
  • 2.
    sudo firmwarepasswd -check
    = Bank check whether a countersign is gear up
  • 3.
    sudo firmwarepasswd -verify
    = Verify your password
  • 4.
    sudo firmwarepasswd -delete
    = Disable the password

5. What tin yous do if you forget the frmware password?

Yous will need to contact Apple tree. Apple volition verify proof of ownership and also ask to verify your identity.

Read:  How to Update Ssd Firmware on Mac

Let’s say a person sold you a Mac with a firmware password on craigslist. Sometime after you demand to enter macOS recovery, merely to find the firmware lock. You are out of luck if y’all have 2011-2017 Mac. You will not be able to notice the previous owner and you do non have proof of ownership.

6. How to remove the firmware countersign with Apple Back up.

If you have proof of ownership, Apple tin remove the firmware password and retain your data for Mac Devices from 2011-2020. They volition walk y’all through a process (Shift-Command-Pick-Command-S) that will show yous a lawmaking that you can give the Apple tree support agent. The agent volition use that lawmaking to send you lot a file and then you lot tin can create a USB boot deejay that will remove the firmware countersign.

You lot tin can take a expect at this great article for a super deep swoop into the firmware password setup. >
https://reverse.put.as/2016/06/25/apple-efi-firmware-passwords-and-the-scbo-myth/

7. Removing the firmware password on a T2 Mac with Apple tree Configurator 2.

Sad that you lot had to scroll this far to become to the betoken of this article. With all the talk about how the firmware countersign selection was removed from M1 Mac Devices, I wanted to explore a picayune history first.

If y’all demand to remove the Firmware countersign from a T2 Mac, all you need to do is Restore BridgeOS with a 2d Mac and Apple Configurator two.

What does an Apple Configurator ii “Restore” practise on a T2 Mac?

  1. Erase the entire SSD (Macintosh Hard disk & macOS Recovery)
  2. Clear Saved NVRAM Settings i.east stored WIFI
  3. Reset whatsoever previous Secure Kick Settings dorsum to default
  4. Reinstall BridgeOS with the latest version available from Apple tree.
  5. Remove the Firmware Password, if information technology was previously set.

Annotation!!!! This only works with a “RESTORE Full ERASE” not a “Revive”. A revive will retain your data and only reinstall BridgeOS. The option will not remove your firmware password.

You lot tin can follow my instructions here >
https://mrmacintosh.com/how-to-restore-bridgeos-on-a-t2-mac-how-to-put-a-mac-into-dfu-manner/

This process is very close to the new M1 Apple Silicon Mac “Erase Mac Process” The difference is that macOS Recovery is even so available later on the process so y’all can easily reinstall macOS.

viii. How long was this new way possible? Does AppleCare even know well-nigh this?

I am always testing new ways to break and ready macOS. When I first confirmed that this new way worked, I was pretty surprised to say the least.

Read:  Cara Reset Hp Samsung J4 Plus

To observe out, I tested with Apple Configurator 2 version 2.7.1 from 2019.

Yup, worked

It is very possible that AC2 was removing the firmware countersign during the BridgeOS restore since the very start.

Later on all this time, did AppleCare even know almost this option? Apple’due south ain instructions only refer to the steps to contact CSS support to remove the countersign via firmware hash / USB drive.

9. What does this mean for education, small-scale & large companies, habitation users, reckoner recyclers, and criminals?

Let’s go over a few situations.

This new procedure does Not disable or remove Activation Lock.

If y’all use the firmware password to protect your data?
– Technically yous are fine because the AC2 Restore process will remove the firmware password & erase all of your data.

If you are a small concern or education institution that is
relying on the firmware password

only does not have Activation Lock enabled. – You lot are most likely trying to prevent students or employees from stealing the Mac then erasing your configuration and reinstalling macOS. The other problem (unlike iOS) a person tin can bypass the Mobile device management screen. In this case, the Mac is long gone.

If you are a computer reseller or recycler.
This is GREAT news for you. You can now wipe the firmware password and reinstall macOS.

ten. What does Apple tree think nigh this?

I reached out to Apple and asked them. The response was that this is expected.

Apple recommends enabling Activation Lock on Macs with the T2 security scrap (2018-2020)

11. How tin I protect my Data on an Intel and M1 Mac?

I concur with Apple’s recommendation, enable Activation Lock.

Additionally, you should also enable FileVault 2.

Enabling FileVault on a T2 Mac with macOS Catalina or newer will forbid an unwanted user from accessing your data in recovery.

If y’all didn’t turn on a firmware password and did non enable FileVault Encryption, your data is WIDE open in macOS recovery. One interesting note, if FV2 is not enabled you will however be prompted for a countersign in Target Deejay Mode.

How to Reset Apple Firmware Password Macbook Air

You May Also Like