How to Unlock Firmware Password on 2012 Mac
You can now remove the firmware password (+ erase all data) on a T2 Mac without Apple Support if you forgot it.
In this article, I will go over the history of the firmware password on Intel Mac computers. After that, I will show you lot a new style how to remove the firmware password (and erase your data) on a T2 Mac from 2018-2020.
(Curl to section vi).
Notation: This information is only for 2006-2020 Intel Mac computers. Apple tree Silicon M1 Mac Devices practice non accept a firmware password.
I will also get over my recommendations on how you can protect your data at the end of this commodity.
I will reply the following questions.
- What does setting a firmware countersign on a Mac exercise?
- What are the differences in firmware passwords from the post-obit years – 2006-2010, 2011-2017 & 2018-2020?
- How to you set the firmware password in recovery.
- How to Enable & Disable Firmware Password in macOS.
- What can you do if you forget the firmware password?
- How to remove the firmware password with Apple tree Support.
- Removing the firmware password on a T2 Mac with Apple Configurator 2.
- How long was this new way possible? Does anyone at AppleCare know about this?
- What does this mean for education, pocket-size & big companies, habitation users, estimator recyclers, and criminals?
- What does Apple call back about this?
- How can I protect my Data on an Intel and M1 Mac?
1. What does setting a firmware password on a Mac do?
The firmware password was designed to protect your Mac. This mode protects confronting someone who wants to become your data. They can’t boot into target deejay way or recovery to admission your files.
Long story brusk, if your Mac lands in the wrong hands and you exercise Non accept the following items enabled beneath, all your data is at risk!.
- Firmware Password
- FileVault 2 Encryption
- Activation Lock / Find My Mac
A person could access your information via Target disk mode or macOS Recovery, fifty-fifty if they do non know your user password!
When you set a firmware password, users who don’t have the countersign tin can’t start up from any deejay other than the designated startup deejay.
The Apple article below details dissimilar startup modes.
If you enable the firmware password, the following startup items are disabled.
Target Deejay Way
(N) – (Remember Netboot?)
Unmarried User Mode
– (Control S)
– (Command V)
Squirt CD-ROM or DVD
– (Eject Key)
– (Shift Key)
The following startup options volition work, but yous will exist prompted for the firmware password.
– (Command R)
– (Command Option R
Command Option Shift R)
If you have the firmware password enabled and you hear someone say “I reset the PRAM” …. NOPE!!!
ii. What are the differences in firmware passwords from the following years – (2006-2010), (2011-2017) & (2018-2020)?
- (2006-2010) – The firmware countersign could be removed past removing the battery, one stick of ram, and resetting the PRAM iii times.
- (2011-2017) Apple changed this when they soldered the memory to the logic board. The just manner to remove the firmware countersign was to contact Apple.
- (2018-2020) Apple tree added the T2 security bit. The chip runs an operating system called BridgeOS.
This Os software can now be re-installed or updated using a 2nd Mac and Apple Configurator 2.
Yous now need to be an admin user that has a SecureToken to admission the Startup Security Utility menu to set and remove the firmware password.
3. How do you ready the firmware password?
The firmware password can be set in three different ways.
- Enable from macOS Recovery.
- Start upwardly from macOS Recovery.
- When the utilities window appears, click Utilities in the menu bar, then choose Startup Security Utility or Firmware Password Utility.
- Click Turn On Firmware Password.
- Enter a firmware password in the fields provided, then click Fix Password.Call up this password.
- Quit the utility, and then choose Apple menu > Restart.
sudo firmwarepasswd -setpasswd
Plough on “Observe My” through iCloud, which enables the firmware countersign & Activation Lock.
iv. How to Enable & Disable Firmware Password in macOS?
You can enable and disable the firmware password inside macOS using terminal.app
sudo firmwarepasswd -setpasswd
= Prepare a new password
sudo firmwarepasswd -check
= Bank check whether a password is ready
sudo firmwarepasswd -verify
= Verify your password
sudo firmwarepasswd -delete
= Disable the countersign
5. What can you exercise if you forget the frmware password?
Yous volition need to contact Apple. Apple will verify proof of ownership and also ask to verify your identity.
Let’s say a person sold yous a Mac with a firmware countersign on craigslist. Sometime later you need to enter macOS recovery, but to observe the firmware lock. Y’all are out of luck if yous have 2011-2017 Mac. You will non be able to observe the previous owner and y’all practise not take proof of buying.
6. How to remove the firmware countersign with Apple tree Support.
If y’all have proof of ownership, Apple tin remove the firmware password and retain your information for Mac Devices from 2011-2020. They will walk you through a process (Shift-Control-Pick-Command-South) that will show you a lawmaking that you tin give the Apple tree support agent. The agent volition apply that code to transport you lot a file so you tin can create a USB boot disk that will remove the firmware countersign.
You can take a look at this slap-up commodity for a super deep dive into the firmware password setup. >
7. Removing the firmware password on a T2 Mac with Apple Configurator 2.
Sorry that you had to curl this far to get to the point of this commodity. With all the talk about how the firmware countersign option was removed from M1 Mac Devices, I wanted to explore a piddling history offset.
If you lot need to remove the Firmware password from a T2 Mac, all you need to do is Restore BridgeOS with a 2nd Mac and Apple Configurator 2.
What does an Apple tree Configurator 2 “Restore” do on a T2 Mac?
- Erase the entire SSD (Macintosh HD & macOS Recovery)
- Clear Saved NVRAM Settings i.eastward stored WIFI
- Reset whatever previous Secure Boot Settings dorsum to default
- Reinstall BridgeOS with the latest version bachelor from Apple tree.
- Remove the Firmware Countersign, if information technology was previously ready.
NOTE!!!! This only works with a “RESTORE Total ERASE” not a “Revive”. A revive volition retain your data and but reinstall BridgeOS. The option will not remove your firmware password.
Yous can follow my instructions here >
This process is very close to the new M1 Apple tree Silicon Mac “Erase Mac Process” The difference is that macOS Recovery is however available after the process so you lot can easily reinstall macOS.
viii. How long was this new way possible? Does AppleCare even know most this?
I am always testing new ways to pause and fix macOS. When I offset confirmed that this new way worked, I was pretty surprised to say the to the lowest degree.
To discover out, I tested with Apple Configurator ii version 2.7.1 from 2019.
It is very possible that AC2 was removing the firmware password during the BridgeOS restore since the very beginning.
After all this fourth dimension, did AppleCare even know about this selection? Apple tree’s ain instructions only refer to the steps to contact CSS support to remove the password via firmware hash / USB bulldoze.
9. What does this mean for teaching, small & large companies, home users, computer recyclers, and criminals?
Let’s go over a few situations.
This new process does NOT disable or remove Activation Lock.
If you utilize the firmware password to protect your data?
– Technically you lot are fine because the AC2 Restore process will remove the firmware password & erase all of your information.
If yous are a small business or education institution that is
relying on the firmware password
only does not have Activation Lock enabled. – You lot are almost likely trying to prevent students or employees from stealing the Mac and then erasing your configuration and reinstalling macOS. The other problem (unlike iOS) a person can bypass the Mobile device management screen. In this example, the Mac is long gone.
If y’all are a computer reseller or recycler.
This is Dandy news for you. You tin now wipe the firmware password and reinstall macOS.
ten. What does Apple recall near this?
I reached out to Apple and asked them. The response was that this is expected.
Apple recommends enabling Activation Lock on Macs with the T2 security chip (2018-2020)
xi. How can I protect my Data on an Intel and M1 Mac?
I agree with Apple tree’southward recommendation, enable Activation Lock.
Additionally, you should besides enable FileVault 2.
Enabling FileVault on a T2 Mac with macOS Catalina or newer volition prevent an unwanted user from accessing your information in recovery.
If you didn’t turn on a firmware password and did non enable FileVault Encryption, your data is Wide open up in macOS recovery. Ane interesting note, if FV2 is not enabled you will still be prompted for a countersign in Target Disk Mode.