Strange behaviour with iCloud Keychain restriction on Mac

awginger
Contributor

So we are using the restrictions to disable the 'Allow iCloud Keychain' setting, as well as disabling 'Allow iCloud Drive'. The Configuration profile is applying to the device and when I sign in with my Apple ID both options are greyed out but the iCloud Keychain option is checked!

After a short amount of time all of my keychain items start to sync to the device! However, if I edit the configuration slightly and save it (so that it reapplies) the check box is removed so iCould Keychain is properly disabled, however it leaves all of my synced items in the local keychain!

Any ideas or should I be raising this as an issue with support?

1 REPLY 1

sshort
Valued Contributor

@awginger I stumbled across this post b/c I'm experiencing the same issue, but I found a solution.

If you have Safari enabled in the iCloud pref pane a weird, reduced version of iCloud Keychain is enabled for things like saved web forms (but I didn't see the full account passwords database come over).

Disabling "Allow iCloud Bookmarks" in a restrictions profile will do the trick (or manually unchecking the Safari box in System Preferences).