Hi Jamf Nation!
I have some questions about what happened in a MacBook after it received the WIPE command, rebooted but without the firmware passcode being authenticated? Could the command be cancelled in any way?
We have a MacBook Air (Retina, 13-inch, 2019) with Intel chipset running macOS 14.3. WIPE command issued and it is now stuck at the user login -> reboot to firmware lock loops.
"Clear Activation Lock" option was chosen when attempting the command, but it says activation lock not found, so the WIPE command was issued without. After the command was sent, the MacBook immediately rebooted into the Firmware lock, which then we realized the passcode is unknown. Attempt to boot or reboot the machine will first goes into the user login page, and ended up at firmware lock after user authentication. We did not reach the steps to enter the 6 digits arbitrary passcode.
I read this from the previous post:
@talkingmoose wrote:If the computer has been protected with a firmware passcode, you’d need the correct PIN to clear that before the computer would be wiped.
Has the data been wiped at this stage? If not, is there a way to undo the WIPE command?
Brought it to Apple Service Center but the technician said it was impossible for them to reset the firmware passcode because it was 'locked'? They have asked for the AppleID initially, and trying to remove the FindMy lock via iCloud. I then explained to them it is a MDM managed device, and they said we have to remove the 'lock' using the managed AppleID before they could reset the firmware, but they are not able to give more details. Further investigate into the configuration profile, he functionality of "Allow iCloud Find My Mac" is enabled, so it might be possible that previous AppleID has the functions turned on. However, the Activation Lock status shown in the inventory of this MacBook is "Not Enabled". What could be the "lock" referred by the technician?
The MacBook was previously used by an ex-senior staff, way before ASM and Jamf Pro was introduced years ago to the organization. Make it worst, the firmware passcode is different from our record. Come to think of it, the firmware lock must be the reason of it not being registered in ASM during the enrollment of all the devices.
Any insights or help for the situation is greatly appreciated.
Thanks!
Doug