Apple Certified Support Professional DEP-2025 Question # 126 Topic 13 Discussion
DEP-2025 Exam Topic 13 Question 126 Discussion:
Question #: 126
Topic #: 13
Your organization deployed managed Mac computers with Apple silicon to its users. They don’t want users to access Startup Security Utility. Which MDM command can your organization use to prevent users from accessing Startup Security Utility?
Apple silicon Macs introduced a new security model, replacing firmware passwords with theSetRecoveryLockMDM command. This command allows administrators to set a recovery password that must be entered before anyone can boot into macOS Recovery. SinceStartup Security Utilityis accessed through Recovery, the Recovery Lock effectively prevents end users from entering this tool without IT authorization. Apple’s learning materials clarify that legacy commands likeSetFirmwarePasswordapply only to Intel-based Macs. FileVault protects data at rest but does not block access to Recovery. PreventSystemSecurityAccess is not a defined MDM command. The correct and modern approach isSetRecoveryLock, which aligns with Apple silicon’s secure boot architecture and enterprise deployment best practices.
[References:Apple Platform Deployment — “Use Recovery Lock with Apple silicon Macs.”, , ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit