
Startup security in macOS
Overview
Startup security policies can help ensure the integrity of a Mac and prevent the installation of older operating system version. It indicates the overall user-configured security state of macOS, such as the booting of a kext or the configuration of System Integrity Protection (SIP).
Startup Disk security policy control for a Mac with Apple silicon
Security policies on a Mac with Apple silicon are supported for each installed operating system. This means that multiple installed macOS instances with different versions and security policies can exist on the same machine. For this reason, an operating system picker has been added to Startup Security Utility.
If changing a security setting would significantly degrade security or make the operating system easier to compromise, users need to restart into recoveryOS by holding the power button (so that malware can’t trigger the signal, only a human with physical access can) in order to make the change. Because of this, a Mac with Apple silicon also won’t require (or support) a firmware password—all critical changes are already gated by user authorization. For more information on SIP, see System Integrity Protection in Apple Platform Security.
Organizations can, however, prevent access to the recoveryOS environment, including the startup options screen, through the use of a recoveryOS password, available with macOS 11.5 or later. For more information, see the recoveryOS password section below.
Security policies
There are three security policies for a Mac with Apple silicon:
Full Security: The the operating system behaves like iOS and iPadOS, and allows only booting software that was known to be the latest that was available at install time.This is the default mode set on a Mac and should be used whenever possible.
Reduced Security: This policy level allows the operating system to run older versions of macOS. Because older versions of macOS inevitably have unpatched vulnerabilities, this security mode is described as Reduced. This is also the policy level you need to configure manually to support booting kernel extensions (kexts) without using a device management service and Automated Device Enrollment with Apple School Manager or Apple Business.
Important: Choose Reduced Security only if your organization depends on legacy kernel extensions that haven’t yet migrated to System Extensions.
Permissive Security: This policy level supports users that are building, signing, and booting their own custom XNU kernels. System Integrity Protection (SIP) needs to be turned off before enabling Permissive Security Mode. For more information, see System Integrity Protection in Apple Platform Security.
For more information on the security policies, see Startup Disk security policy control for a Mac with Apple silicon in Apple Platform Security.
recoveryOS password
A Mac with Apple silicon with macOS 11.5 or later supports setting a recoveryOS password using a device management service. Unless the user enters the recoveryOS password, they can’t access the recovery environment, including the Startup Options screen. You can set a recoveryOS password only using a device management service, and for the service to update or remove an existing password, you also need to provide the current password. Because you can set, update, or remove the recoveryOS password only through the service, unenrolling a Mac that has a set recoveryOS password from that service also removes the password. Device management service administrators can verify the correct recoveryOS password is set by using the Verify Recovery Lock command.
Note: Setting a recoveryOS password doesn’t prevent the restoration of a Mac computer with Apple silicon through DFU Mode using Apple Configurator, which also cryptographically renders the previous data on the Mac inaccessible.