As most of you are aware the new Apple Silicon arm64 Macs no longer support a Firmware password and it looks like Apple suggests we use one or both of the following:
• File Vault (Encrypts the users data)
• Recovery password (Stops the machine entering recovery mode)
However setting any of these still allows users to put an M1 into DFU mode and once in DFU mode the machine can be factory reset. During the setup the client can then select “I don’t have an internet connection”, the machine will prompt that you need one, but doing this four times bypasses all DEP Enrolment.
Has anyone else come across this and do you have any suggestions on a solution.
At the moment, the only solution I can think of will be for Apple to set:
- Activation Lock which is only available for iOS
- Stop a DEP enrolled Silicon Device from skipping the internet connection which is how it is for iOS
I understand that under standard employment if you alter the security settings on your work issued device this can result in termination of your employment contract. This area is harder to in-force with students at a school and maybe a short term solution for us might be to replace students that change security settings on a school issued laptop to a second hand intel laptop.
