Sophos Mobile: Activation Lock and device name settings for iPhone and iPad
Under Setup > Apple setup > iOS & iPadOS, there are two distinct settings: Activation Lock bypass concerns the bypass code for Apple Activation Lock on supervised iPhones and iPads; Synchronize device name determines whether Sophos Mobile uses the name chosen by the user on the device. These are general Apple settings, not Apple Business enrollment profiles or a command to unlock an individual device.
Before handing over or wiping a device: For user-linked Activation Lock, the bypass code comes from the device; for organization-linked Activation Lock, the device management service (MDM) creates it. The Sophos setting describes supervised devices sending the device-generated code; this does not establish that Sophos Mobile holds the organization-linked MDM code. Before changing the state of a specific device, verify and document its lock type, code origin, secure custody, and authorized unlock path; if that evidence is missing, pause the wipe or handoff and consult the responsible device owner. Turning on a setting does not prove that Sophos Mobile has a bypass code for that device. Check the specific device record and its management status first. Release from Organization, removal from management, resetting the device, and turning off Activation Lock are separate operations; the reactivation paths below do not replace separate authorization for a reset or device handoff.
Activation Lock bypass for supervised devices
After a reset, Apple Activation Lock can tie reactivation to the previous user’s Apple Account. According to Sophos, supervised devices with Activation Lock enabled send their bypass code to Sophos Mobile when this setting is on. The code may help with later reactivation if the previous Apple Account is unavailable. Not every enrolled iPhone or iPad is automatically supervised: verify the supervision status of the device in question before planning any action.
Before allowing user-linked Activation Lock: If a device policy is to allow the user to enable Activation Lock, the device management service must first retrieve and securely store the bypass code generated by that specific device. Document successful retrieval, association with the correct device, and approved access to the protected storage before granting this permission. If Find My is already on, the lock may become active as soon as permission is granted. The Sophos Activation Lock bypass setting for receiving the code and policy permission for user-linked Activation Lock are separate decisions; neither enabling collection nor approving a custody procedure replaces actual retrieval for the specific device. If evidence is missing, do not grant permission; consult the responsible device owner. If the lock is already active, instead check the existing state and the reactivation paths described below; this preventive sequence does not guarantee that the code can be retrieved retroactively.
- In Sophos Mobile Admin, open Setup > Apple setup > iOS & iPadOS and check the Activation Lock bypass setting. Changing settings requires the Sophos Mobile Administrator role (in Sophos Fusion: Super Admin or Admin); Helpdesk cannot configure settings. Enable it only after the custody and access procedure described below has been approved.
- After the setting is enabled, the affected device must have synchronized with Sophos Mobile again. The code generated by the iPhone or iPad can be retrieved from the device for at most 15 days after it is first supervised, unless a device management service has explicitly retrieved and cleared it from the device earlier. If it is not retrieved within that window, this device-generated code can no longer be retrieved afterward. This is Apple’s device-side retrieval limit, not a statement about when or for how long Sophos Mobile escrows a code. Turning on the setting later and then synchronizing does not prove that a code can be retrieved retroactively, especially for a device supervised for longer. Do not assume that a device already removed from management or reset can send its code afterward.
- For a specific device, check Devices > [device] > Device properties for ActivationLockBypassCode. Before resetting, removing from management, handing over, or migrating MDM, establish for that specific device whether a usable code has already been securely escrowed and is accessible through the approved process; neither the setting nor synchronization replaces this proof. Treat the value as a credential: do not record it in tickets, screenshots, or broadly accessible exports. The mere presence of the property is not a completed activation test.
Approve custody before enabling the setting or changing management services: The responsible device owner must approve a written procedure before enabling the setting and before offboarding or MDM migration: authorized roles and people for retrieval and use, restricted storage and protected backups, access logging and regular review, a justified retention and deletion decision, and responsibility and a secure handoff method when changing services. When changing MDM services, you should transfer the secured codes and backups for all affected enrolled devices or have their Activation Locks removed through an authorized path. Before any change, verify actual availability and approved access for each device; if there is no confirmed path, pause the change and consult the responsible device owner. Code values and copies do not belong on this page or in the review evidence. The retention period and export and deletion behavior in Sophos Mobile are not established here; do not treat either turning off the setting or changing MDM as a guarantee of deletion or transfer.
If the property is missing, first check supervision, Activation Lock status, and synchronization after the setting was enabled. Do not reset or release the device as a test. Apple distinguishes user-linked from organization-linked Activation Lock: the Apple Business action matrix marks direct removal of a user-linked lock by a device management service as No, but removal through Apple Business, provided its requirements are met, as Yes. This is not a blanket prohibition on an MDM bypass: according to Apple’s deployment guide, a device management service can also remotely remove a user-linked lock using a bypass code previously retrieved from and escrowed for the supervised device; alternatively, the code can be used directly on the device. This does not establish whether Sophos offers that remote code-based option in a given case. The documented Sophos action Actions > Remove Activation Lock requires the device to still be enrolled in Sophos Mobile and, according to Sophos, does not work on devices with at least two SIM/eSIM slots, including current iPhone models. That action is not equivalent to using a bypass code. Choose a suitable path only on the basis of the specific device’s status and with the organization’s authorization.
Important for Apple Business: According to Apple, turning off Activation Lock there requires the organization to have added the device to Apple Business before the lock was enabled and not to have released it; it also requires a role with permission to remove Activation Lock. For Release from Organization through the Apple Business interface, the signed-in user separately needs a role with permission to release devices. That is not the only possible way to release a device: according to Apple, a linked device management service can also release devices without signing in to Apple Business if its release option is enabled; the option is enabled by default when a service is added but can be deselected. An authorized Apple reseller can also release a device. A signed-in user’s lack of release permission does not rule out these other paths. Whether release through a service is actually permitted and authorized by the organization belongs in a separately approved offboarding/release review; do not initiate an automatic release or change the service configuration here. After release, Apple Business can no longer manage Activation Lock for the device. According to Apple, a released device can be added again through a separate procedure; that does not undo the release or preserve management of the lock in the meantime. Do not use Release as a supposed fix for a missing bypass-code property. Turning off Activation Lock bypass later is likewise not an established way to undo locks already enabled and guarantees neither deletion of a previously received code nor a subsequent unlock. Resolve such cases individually with authorized device owners before the device’s state changes.
Reactivate a returned iPhone or iPad
The following paths apply to a supervised device that has been returned or recovered, with authorization to return it to service when the previous user’s Apple Account credentials are unavailable. First establish ownership, device identity, lock type, and authorization. Do not remove a lock on a device that is still missing as a supposed recovery test. A factory reset erases the device’s data and cannot be undone; if a reset is still required, check backups and separate authorization for erasure beforehand.
Still enrolled: Remove Activation Lock before the reset
This path requires existing Sophos Mobile enrollment. The restriction described above for devices with at least two SIM/eSIM slots still applies. For such a device, assess the authorized Apple Business path and its prerequisites instead; entering a code on the device is a separate path.
- In Sophos Mobile Admin, open Devices and click the name of the unambiguously identified device.
- On Show device, select Actions > Remove Activation Lock. Sophos Mobile sends a task to the device to turn off Activation Lock.
- Verify that this task has completed successfully before resetting. A created, notified, or pending task is not enough. If completion is unconfirmed or contradictory, do not reset; consult the responsible Mobile/Apple administrators.
- Reset the device to factory settings only after the task has completed and separate authorization concerning backups and erasure has been obtained.
- Then complete activation on the device. According to Sophos, signing in with the previous user’s Apple Account is no longer required. Verify this expected state on the specific device; the task notification alone does not prove successful activation. If the previous account is still required, stop the return-to-service process and escalate.
Through Apple Business: turn off Activation Lock with authorization
This path is an option for an iPhone or iPad belonging to the organization if it was added to Apple Business before the lock was enabled and has not been released. Assignment to a device management service is not required. The signed-in Apple Business role must have permission to remove Activation Lock; a Sophos Mobile role alone is not sufficient. Before taking action, verify ownership, the serial number, authorization to return the device to service, and these prerequisites. If evidence is missing, stop and consult the Apple administrators. Release from Organization is not a step in this unlock path.
- Sign in to Apple Business as a user with the required permission and open Devices > Inventory. Search for the device if needed, select it, and match its serial number against the returned device and the approved inventory evidence; do not rely on the device name alone.
- Under Details, check that Activation Lock is on. Compare the displayed user-linked or organization-linked state with the known lock type. If the device is missing or the state is contradictory, do not initiate any action; clarify the prerequisites with the Apple administrators.
- Select More > Turn Off Activation Lock. Read the dialog carefully: turning off the lock through this action cannot be undone. Only for the unambiguously identified device with the required authorization, acknowledge I understand that this cannot be undone and select Confirm. Do not select release of the device from the organization instead.
- View the newly created activity and wait for it to complete; only then select Done. A merely created or still-running activity is not enough. If there is an error or completion is unclear, stop and consult the Apple administrators before performing any pending reset.
- Verify actual activation or setup on the device: it must be possible without authenticating as the previous user. Any pending reset still requires separate authorization concerning backups and erasure; do not reset just to test. According to Apple, when erasing through Erase All Content and Settings or Apple Configurator, the device may still indicate that Activation Lock is on even though setup is possible without the previous account. Therefore, neither that indication nor activity completion alone is definitive proof of activation. If the previous account is still required during actual setup, stop the return-to-service process and escalate.
Already unenrolled: use an existing bypass code on the device
If the device has already been unenrolled from Sophos Mobile, for example after a factory reset by the user, Sophos describes reactivation using a bypass code. This requires Activation Lock bypass to have been enabled beforehand and subsequent device synchronization to have occurred. Verify the existing code and its secure custody as described above rather than assuming it can be retrieved afterward from the unenrolled device.
- In Devices, click the name of the correct device. On Show device > Device properties, look for ActivationLockBypassCode. The property value is the bypass code. Use only the code verified for this device and available through approved secure access. If the device record or a usable code is missing, stop and escalate to the responsible device owner. Code availability after deleting the record has not been established.
- Turn on the device that has already been reset to factory settings. If a reset is still required, the backup and erasure authorizations above must be obtained first; do not repeat an existing reset to test the code.
- On the Apple Account sign-in page, enter the bypass code without dashes in the Password field. Leave the Apple Account field empty.
- Complete the remaining activation steps and check on the device whether activation succeeds. If the code is rejected or the previous account is still required, stop and escalate. Do not record code values in tickets or review evidence.
Successful activation does not restore erased data. Before returning the device to service, separately check required backups, reenrollment, and protection status. These procedures are supported by documentation, not tested in a tenant or on a device.
Choose Synchronize device name deliberately
When Synchronize device name is on, Sophos Mobile uses the name the user set on the device. When it is off, Sophos Mobile uses the name assigned during device enrollment. This affects naming in the managed inventory, not Activation Lock.
For inventories with a fixed naming scheme, a stable enrollment name may be more useful; if matching the name actually displayed on the device matters more, synchronization may be preferable. After choosing, compare the affected device record with the expected name. If they differ, first check which name was recorded at enrollment and whether the device has synchronized since the change. This setting alone does not imply that the device is renamed in iOS or iPadOS.
Limit of verification: The menu paths and field properties described here are supported by vendor documentation, not tested in practice in a Sophos Mobile tenant or on a device. In particular, the effect of subsequently disabling the bypass setting, the retention period of a previously received code, and successful reactivation have not been verified here.