Skip to content

New Recovery Password Library Item Thwarts Unauthorized Startups

New Recovery Password Library Item Thwarts Unauthorized Startups

Kandji's new Recovery Password Library Item allows you to configure and apply recovery passwords (to Mac computers with Apple silicon) and EFI firmware passwords (for Intel-based Mac computers), in order to protect against unauthorized startup commands.

Recovery Password 2_edit

This new Library Item supports automatically generating per-computer passwords, with the option of configuring time-based rotation (similar to the functionality for our rotating FileVault recovery keys); alternatively, you can manually set a static password. (We recommend the per-computer option.)

Recovery password 3_edit

If you’ve migrated from another device management solution, and had firmware passwords configured on Intel-based Mac computers, you can also provide up to 20 of those known passwords to Kandji and they will be automatically updated. 

For end-users, the experience will depend on the kind of Mac they have. For Mac computers with Apple silicon, the recovery password will be applied without any user interaction. For Intel-based Mac computers, users will be prompted to restart within 30 minutes after a legacy firmware password is applied, whether for the first time or when being rotated; this restart cannot be deferred.

For more details on recovery passwords in general, see Apple's documentation on startup security in macOS and firmware password protection for Intel-based Mac computers. For more on our new Library Item, check out the knowledge base article.

New SSH Library Item

We’ve also added a new Library Item to help manage the SSH server and SSH client configurations across your macOS fleet, further expanding automation workflows.
SSH library item_edit

Admins can leverage this new Library Item to quickly meet or exceed CIS and NIST security standards. To learn more about the SSH Library Item, see our knowledge base article.

Recent Articles

Featured image: TIL: How To Keep Bad Apps Out of Your Mac Fleet
Iru Team 1 min read

TIL: How To Keep Bad Apps Out of Your Mac Fleet

Need to stop bad apps from infiltrating your Mac fleet? In this TIL episode, Andy Rana shows how to use Kandji's App Blocking library item to keep unauthorized apps off managed devices. Learn how to spot bad apps, set blocking rules, and see the workflow from setup to end-user experience.

TIL
Featured image: Kandji Referral Program
Iru Team 2 min read

Introducing the Kandji Referral Program

If you’ve ever raved about Kandji to a friend, colleague, or peer, you’re in good company. Our customers can’t help but share it - whether it’s in a Slack community, during a coffee break, or during a “you’ve got to check this out” moment. Those recommendations carry more weight than any ad ever could, because they come from someone who’s been there, done that, and solved the problem.

Inside Iru
Featured image: The Kids Aren’t Alright: A Threat Intel Dad’s View of the Internet
Alex Gartner 4 min read

The Kids Aren’t Alright: A Threat Intel Dad’s View of the Internet

Opinion

See Iru in action

Discover why thousands of teams choose Iru

By submitting this form I agree to Iru’s Privacy Policy and consent to be contacted by Iru about its products and services.

Stay up to date

Iru's weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.