Hi all,
We have enabled EFI for our mac users. Randomly some machines are locked and require EFI pwd.
Issue happens often after a reboot.
Anyone faced the issue ? Any tricks here?
Regards,
Mohamed
Hi all,
We have enabled EFI for our mac users. Randomly some machines are locked and require EFI pwd.
Issue happens often after a reboot.
Anyone faced the issue ? Any tricks here?
Regards,
Mohamed
Best answer by mm2270
Has happened to us as well. We had a spate of machines located half way around the world where this happened to, which was a pain to say the least. Fortunately it seems to have calmed down lately.
Some reasons why a Mac may boot to Recovery and get locked at the firmware password screen are, if a user forgets their password and follows the instructions that appear at the login screen to force shut down and reboot the Mac to recovery (wish there was some way to prevent that message, but this one boiled down to user training to not do that). I've also seen it happen when installing an OS update, possibly one that went a little sideways in application. Lastly, I had a case of someone who kept using the laptop until the battery drained down to 0 (I mean, the OS warns you it's going to power off if you don't plug it in soon, so how they managed that one I don't know)
As for fixing this, unfortunately outside of user training as I mentioned, there isn't any real way to prevent this. However, we're in the process now of moving away from using a single EFI password across all devices and treating it more like the Personal Recovery Key for FileVault, where each Mac gets it own password and can be escrowed into Jamf (in an Extension Attribute) I had to craft a whole process using scripts around this, including encrypting the password as stored inside Jamf so it's not just in plain text, for a little extra security.
Our new process is working well in testing. We've still to roll it out, but it will be a big help going forward. It means in emergency scenarios, like the ones where devices in another country with no IT personnel nearby to help locked themselves, we can send them the password to their Mac, knowing that it only applies to theirs and no-one else's. It does compromise some security though, since part of the reason for an EFI password is to prevent a user from alt booting their Mac or doing something like disabling SIP. But we have things in place to catch any instances of this too and report on them, plus, I'm not too concerned any of our users will do those things to begin with.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.