Lockdown Mode on macOS: Protecting High-Risk Users
What Lockdown Mode restricts on macOS, how to enable it, how it affects MDM, and the companion controls high-risk users need, from ADP to security keys.
Most hardening work assumes an attacker who is opportunistic: phishing kits, commodity malware, stolen passwords. A small group of people face something different. Journalists, human rights defenders, senior executives, politicians and their staff can be targeted by well-funded operators using mercenary spyware delivered through zero-click exploits. For them, Apple built Lockdown Mode, an optional, extreme protection mode that deliberately reduces attack surface at the cost of functionality.
This guide covers what Lockdown Mode changes on macOS, how to enable and verify it, how it interacts with managed fleets, and the surrounding controls that matter just as much for high-risk users.
What Lockdown Mode is
Lockdown Mode arrived with macOS Ventura and iOS 16 and has been extended in later releases. It is not a single switch that "turns on security"; it is a bundle of restrictions targeting the features most commonly abused as remote entry points. Complex parsers for message attachments, just-in-time JavaScript compilation, and unsolicited invitations from unknown contacts all expose code paths an attacker can reach without the victim doing anything. Lockdown Mode removes or narrows those paths.
The trade-off is intentional. Apple describes it as a mode that makes some apps, websites and features work differently, and some not at all.
What it restricts
Apple documents the restrictions in its support article on Lockdown Mode and updates the list over time. The core areas on the Mac are:
| Area | Behaviour with Lockdown Mode on |
|---|---|
| Messages | Most attachment types other than certain images, video and audio are blocked. Some features such as links and link previews are unavailable. |
| Web browsing | Certain complex web technologies, including JIT JavaScript compilation, are disabled unless the user excludes a trusted site. |
| FaceTime | Incoming calls are blocked from people you have not previously called. |
| Apple services | Incoming invitations for services, such as invitations to manage a home in the Home app, are blocked unless you have previously invited that person. |
| Photos | Shared albums are removed and new shared album invitations are blocked. |
| Configuration profiles and MDM | New configuration profiles cannot be installed and the device cannot enroll in MDM while the mode is on. |
| Wired accessories | On iPhone and iPad, wired connections to computers and accessories are blocked while the device is locked. |
Several of these are primarily iPhone behaviours, but the Mac matters too: a high-risk person's laptop holds the same Messages history, iCloud data and browser sessions.
What it does not do
Lockdown Mode is not antivirus, not a firewall and not a replacement for patching. It does not stop a user from opening a malicious attachment that is still permitted, and it does not protect accounts from password phishing. It shrinks the zero-click surface; everything else in this series still applies.
How to enable it
On macOS:
- Open System Settings > Privacy & Security.
- Scroll to Lockdown Mode and click Turn On.
- Confirm, authenticate, and restart when prompted.
Repeat on every device the person uses: iPhone, iPad, Apple Watch where supported, and each Mac. Enabling it on one device does not enable it on the others.
Per-site exclusions in Safari
Some sites break without the disabled web technologies. Safari lets the user exclude individual trusted sites from Lockdown Mode web restrictions through the website settings for that site. Keep exclusions to a minimum, review them periodically, and never exclude a site because a link in a message told you to. Other browsers that use their own engines are not governed by these Safari web restrictions in the same way, which is one reason to standardise high-risk users on Safari.
Lockdown Mode and managed fleets
The MDM restriction is the most important operational detail for admins. Because a Mac with Lockdown Mode on cannot enroll or accept new profiles, sequence the work:
- Enroll the Mac in MDM (ideally via Automated Device Enrollment) and deliver the baseline profiles first. See the MDM and configuration profiles guide.
- Confirm FileVault, updates and security settings are applied.
- Have the user enable Lockdown Mode.
- If a new profile must be installed later, the user temporarily turns Lockdown Mode off, the profile is delivered, and the mode is turned back on.
Test your line-of-business apps and SSO flows on a pilot Mac with Lockdown Mode enabled before rolling it out to a protected group, since web-based sign-in pages are a common source of breakage.
Apple threat notifications
Apple sends threat notifications to users it believes have been individually targeted by state-sponsored or mercenary spyware attacks. According to Apple, notifications are shown at the top of the page after signing in to the Apple Account website and are also sent by email and iMessage to the addresses and phone numbers associated with the account.
Treat a notification seriously but carefully:
- Apple states these notifications never ask users to click links, open files, install apps or profiles, or provide account passwords or verification codes. Any message that does is suspicious in itself.
- Verify by signing in directly at the Apple Account website, not through a link.
- Enable Lockdown Mode on all devices and bring in qualified incident response help rather than attempting forensics alone.
Companion controls for high-risk users
Lockdown Mode is one layer. The account and data around the device matter as much.
Advanced Data Protection for iCloud
Standard iCloud data protection already end-to-end encrypts categories such as Keychain and Health data. Advanced Data Protection extends end-to-end encryption to most remaining categories, including iCloud Backup, iCloud Drive, Photos and Notes. iCloud Mail, Contacts and Calendars remain outside it because they interoperate with global email and calendar standards.
Before enabling it, the user must set up a recovery contact or a recovery key, because Apple can no longer help recover that data. All devices signed in to the account must run a software version that supports the feature. Availability can vary by country; for example, Apple stopped offering it to new users in the United Kingdom in 2025.
Security keys for the Apple Account
Apple Accounts support FIDO-certified hardware security keys as a second factor. When enabled, a physical key replaces six-digit verification codes, which makes real-time phishing of the second factor much harder. Apple requires at least two keys to be registered so that losing one does not lock the user out. Managed Apple Accounts and child accounts are not supported.
The rest of the baseline
- Keep macOS current; high-risk users should install updates as soon as they are released. See the software updates guide.
- Ensure FileVault is on and the recovery key is escrowed (FileVault guide).
- Run as a standard user day to day (accounts guide).
- Review privacy permissions regularly (TCC guide).
Travel hygiene
Border crossings and hotel rooms change the threat model from remote to physical.
| Situation | Recommendation |
|---|---|
| Crossing borders | Consider a dedicated travel Mac with minimal data, signed in to a separate account where policy allows |
| Before inspection points | Shut the Mac down fully rather than sleeping it, so FileVault-protected data requires the password to unlock |
| Hotel rooms | Keep devices with you or shut down; do not leave them sleeping and unattended |
| Public networks | Use a trusted VPN and avoid unknown USB chargers and accessories |
| On return | Review sign-in history, check for unexpected profiles, and update devices before reconnecting to corporate resources |
Verify it
There is no supported command-line switch for Lockdown Mode itself; confirm its state in System Settings > Privacy & Security, where the section shows whether it is on. Then verify the surrounding posture:
fdesetup status
csrutil status
spctl --status
profiles status -type enrollment
softwareupdate --list
Expected results on a well-prepared high-risk Mac:
FileVault is On.
System Integrity Protection status: enabled.
assessments enabled
Enrolled via DEP: Yes
MDM enrollment: Yes (User Approved)
The enrollment line reflects enrollment completed before Lockdown Mode was turned on. A functional check is also useful: attempting to install a new configuration profile while Lockdown Mode is on should fail.
Common pitfalls
- Enabling before enrolling. The Mac cannot then enroll in MDM until the mode is turned off.
- Protecting only the phone. Every device on the account needs Lockdown Mode.
- Too many Safari exclusions. Each exclusion restores attack surface for that site.
- Skipping recovery setup for ADP. Without a recovery contact or key, data loss is permanent.
- One security key. Register at least two and store the spare safely.
- Recommending it to everyone. Broad deployment creates support load without matching benefit; target the people who genuinely face advanced threats.
Checklist
- Identified the users who genuinely face targeted threats
- Enrolled and baselined their Macs before enabling Lockdown Mode
- Enabled Lockdown Mode on every Apple device they use
- Tested critical apps and SSO with the mode on
- Enabled Advanced Data Protection with a recovery method in place
- Registered at least two security keys for the Apple Account
- Briefed users on threat notifications and travel hygiene