Skip to content

Lockdown Mode on macOS: Protecting High-Risk Users

What Lockdown Mode restricts on macOS, how to enable it, how it affects MDM, and the companion controls high-risk users need, from ADP to security keys.

Published on 8 min read

Most hardening work assumes an attacker who is opportunistic: phishing kits, commodity malware, stolen passwords. A small group of people face something different. Journalists, human rights defenders, senior executives, politicians and their staff can be targeted by well-funded operators using mercenary spyware delivered through zero-click exploits. For them, Apple built Lockdown Mode, an optional, extreme protection mode that deliberately reduces attack surface at the cost of functionality.

This guide covers what Lockdown Mode changes on macOS, how to enable and verify it, how it interacts with managed fleets, and the surrounding controls that matter just as much for high-risk users.

What Lockdown Mode is

Lockdown Mode arrived with macOS Ventura and iOS 16 and has been extended in later releases. It is not a single switch that "turns on security"; it is a bundle of restrictions targeting the features most commonly abused as remote entry points. Complex parsers for message attachments, just-in-time JavaScript compilation, and unsolicited invitations from unknown contacts all expose code paths an attacker can reach without the victim doing anything. Lockdown Mode removes or narrows those paths.

The trade-off is intentional. Apple describes it as a mode that makes some apps, websites and features work differently, and some not at all.

What it restricts

Apple documents the restrictions in its support article on Lockdown Mode and updates the list over time. The core areas on the Mac are:

AreaBehaviour with Lockdown Mode on
MessagesMost attachment types other than certain images, video and audio are blocked. Some features such as links and link previews are unavailable.
Web browsingCertain complex web technologies, including JIT JavaScript compilation, are disabled unless the user excludes a trusted site.
FaceTimeIncoming calls are blocked from people you have not previously called.
Apple servicesIncoming invitations for services, such as invitations to manage a home in the Home app, are blocked unless you have previously invited that person.
PhotosShared albums are removed and new shared album invitations are blocked.
Configuration profiles and MDMNew configuration profiles cannot be installed and the device cannot enroll in MDM while the mode is on.
Wired accessoriesOn iPhone and iPad, wired connections to computers and accessories are blocked while the device is locked.

Several of these are primarily iPhone behaviours, but the Mac matters too: a high-risk person's laptop holds the same Messages history, iCloud data and browser sessions.

What it does not do

Lockdown Mode is not antivirus, not a firewall and not a replacement for patching. It does not stop a user from opening a malicious attachment that is still permitted, and it does not protect accounts from password phishing. It shrinks the zero-click surface; everything else in this series still applies.

How to enable it

On macOS:

  1. Open System Settings > Privacy & Security.
  2. Scroll to Lockdown Mode and click Turn On.
  3. Confirm, authenticate, and restart when prompted.

Repeat on every device the person uses: iPhone, iPad, Apple Watch where supported, and each Mac. Enabling it on one device does not enable it on the others.

Per-site exclusions in Safari

Some sites break without the disabled web technologies. Safari lets the user exclude individual trusted sites from Lockdown Mode web restrictions through the website settings for that site. Keep exclusions to a minimum, review them periodically, and never exclude a site because a link in a message told you to. Other browsers that use their own engines are not governed by these Safari web restrictions in the same way, which is one reason to standardise high-risk users on Safari.

Lockdown Mode and managed fleets

The MDM restriction is the most important operational detail for admins. Because a Mac with Lockdown Mode on cannot enroll or accept new profiles, sequence the work:

  1. Enroll the Mac in MDM (ideally via Automated Device Enrollment) and deliver the baseline profiles first. See the MDM and configuration profiles guide.
  2. Confirm FileVault, updates and security settings are applied.
  3. Have the user enable Lockdown Mode.
  4. If a new profile must be installed later, the user temporarily turns Lockdown Mode off, the profile is delivered, and the mode is turned back on.

Test your line-of-business apps and SSO flows on a pilot Mac with Lockdown Mode enabled before rolling it out to a protected group, since web-based sign-in pages are a common source of breakage.

Apple threat notifications

Apple sends threat notifications to users it believes have been individually targeted by state-sponsored or mercenary spyware attacks. According to Apple, notifications are shown at the top of the page after signing in to the Apple Account website and are also sent by email and iMessage to the addresses and phone numbers associated with the account.

Treat a notification seriously but carefully:

  • Apple states these notifications never ask users to click links, open files, install apps or profiles, or provide account passwords or verification codes. Any message that does is suspicious in itself.
  • Verify by signing in directly at the Apple Account website, not through a link.
  • Enable Lockdown Mode on all devices and bring in qualified incident response help rather than attempting forensics alone.

Companion controls for high-risk users

Lockdown Mode is one layer. The account and data around the device matter as much.

Advanced Data Protection for iCloud

Standard iCloud data protection already end-to-end encrypts categories such as Keychain and Health data. Advanced Data Protection extends end-to-end encryption to most remaining categories, including iCloud Backup, iCloud Drive, Photos and Notes. iCloud Mail, Contacts and Calendars remain outside it because they interoperate with global email and calendar standards.

Before enabling it, the user must set up a recovery contact or a recovery key, because Apple can no longer help recover that data. All devices signed in to the account must run a software version that supports the feature. Availability can vary by country; for example, Apple stopped offering it to new users in the United Kingdom in 2025.

Security keys for the Apple Account

Apple Accounts support FIDO-certified hardware security keys as a second factor. When enabled, a physical key replaces six-digit verification codes, which makes real-time phishing of the second factor much harder. Apple requires at least two keys to be registered so that losing one does not lock the user out. Managed Apple Accounts and child accounts are not supported.

The rest of the baseline

Travel hygiene

Border crossings and hotel rooms change the threat model from remote to physical.

SituationRecommendation
Crossing bordersConsider a dedicated travel Mac with minimal data, signed in to a separate account where policy allows
Before inspection pointsShut the Mac down fully rather than sleeping it, so FileVault-protected data requires the password to unlock
Hotel roomsKeep devices with you or shut down; do not leave them sleeping and unattended
Public networksUse a trusted VPN and avoid unknown USB chargers and accessories
On returnReview sign-in history, check for unexpected profiles, and update devices before reconnecting to corporate resources

Verify it

There is no supported command-line switch for Lockdown Mode itself; confirm its state in System Settings > Privacy & Security, where the section shows whether it is on. Then verify the surrounding posture:

fdesetup status
csrutil status
spctl --status
profiles status -type enrollment
softwareupdate --list

Expected results on a well-prepared high-risk Mac:

FileVault is On.
System Integrity Protection status: enabled.
assessments enabled
Enrolled via DEP: Yes
MDM enrollment: Yes (User Approved)

The enrollment line reflects enrollment completed before Lockdown Mode was turned on. A functional check is also useful: attempting to install a new configuration profile while Lockdown Mode is on should fail.

Common pitfalls

  • Enabling before enrolling. The Mac cannot then enroll in MDM until the mode is turned off.
  • Protecting only the phone. Every device on the account needs Lockdown Mode.
  • Too many Safari exclusions. Each exclusion restores attack surface for that site.
  • Skipping recovery setup for ADP. Without a recovery contact or key, data loss is permanent.
  • One security key. Register at least two and store the spare safely.
  • Recommending it to everyone. Broad deployment creates support load without matching benefit; target the people who genuinely face advanced threats.

Checklist

  • Identified the users who genuinely face targeted threats
  • Enrolled and baselined their Macs before enabling Lockdown Mode
  • Enabled Lockdown Mode on every Apple device they use
  • Tested critical apps and SSO with the mode on
  • Enabled Advanced Data Protection with a recovery method in place
  • Registered at least two security keys for the Apple Account
  • Briefed users on threat notifications and travel hygiene