How to prevent Recovery Mode in 2017 Intel Macbooks

Morningside
Contributor II

Hi there.  My school has a pool of 40 2017 MacBook Airs running Mojave that the kids use.  They are not assigned 1 to 1, rather they are in a couple of carts and the kids pull from the pool randomly.

One or more of our kids are quite savvy and have figured out how to boot into Recovery Mode and change passwords, and wreak other havoks.  

What is the recommended method for preventing students from entering recovery mode, single user mode, booting to installer thumb drives, etc.?

1 ACCEPTED SOLUTION

junjishimazaki
Contributor III

To prevent users from booting to single user mode and recovery mode is by enabling and setting a firmware password. Secure boot should already be enabled by default to prevent booting from external devices.

View solution in original post

5 REPLIES 5

junjishimazaki
Contributor III

To prevent users from booting to single user mode and recovery mode is by enabling and setting a firmware password. Secure boot should already be enabled by default to prevent booting from external devices.

View solution in original post

AJPinto
Contributor III

For intel Macs you can put an EFI password on the device which will lock recovery behind a password. This wont work on Apple Silicon Macs, and the function that locks that out on Apple Silicon is broke in JAMF right now.

 

https://docs.jamf.com/10.30.0/jamf-pro/administrator-guide/Setting_or_Removing_an_EFI_Password.html

 

Thanks for the info there AJPinto. I wasn't aware of that. My org doesn't have any M1 macs yet. 

William56
New Contributor

Hello,

Apple Recovery mode is a default set of tools in your macOS created to offer you safe Mac boot options to recover your Mac from software issues. First introduced in 2011 with the release of Mac OS X Lion, the ability to boot Mac in Recovery mode greatly simplified macOS reinstallation while giving users more control. 

MacBook Recovery mode also makes using your Mac more secure. For example, if your Mac has a T2 security chip and you want to use macOS from an external drive, then your only option is to boot into Recovery Mac mode.

MacJunior
Contributor

@AJPinto Recovery lock password for M1 Macs works perfectly now on the latest release 10.33, check it out