Published 2026-09-07 · LuckyMDM Blog
Start with the conclusion: an iPhone can be locked twice, by two systems that have nothing to do with each other, and confusing them is the single most common cause of a failed trade-in or a device that will not re-enrol. Activation Lock is a user-level theft deterrent tied to an Apple Account. MDM supervision lock - often called configuration lock - is an organisation-level asset control tied to the device serial number in Apple Business Manager or Apple School Manager. One is stored against an account, the other against a serial number. An erase clears neither, and they are released in a specific order.
| Activation Lock | MDM supervision lock (configuration lock) | |
|---|---|---|
| Purpose | Theft deterrence | Asset control and enrolment enforcement |
| Created by | Find My being turned on by the user | Device serial number assigned to an MDM server in ABM/ASM, via Automated Device Enrollment |
| Keyed to | The user's Apple Account | The device serial number, on Apple's servers |
| Survives an erase | Yes | Yes |
| Who can release it | The account holder, or the organisation via a bypass code, or Apple with proof of ownership | The organisation that owns the ABM record |
| Where it is checked | Apple activation servers during Setup Assistant | Apple activation servers during Setup Assistant, which redirect the device to the assigned MDM server |
The third row is the one that matters operationally. Because the supervision record is keyed to a serial number and held on Apple's servers, a device can be erased, restored and re-activated as many times as you like and it will still be pulled back to the same MDM server. Local data can be wiped; a server-side record cannot. This is what makes supervision lock the control that survives in a rental or fleet context, and it is also what makes it easy to leave behind by accident.
Several details are widely misreported, so it is worth stating what the documentation actually says:
IsActivationLockEnabled is not a reliable reflection of Activation Lock state, because the device can report either a false positive or a false negative.Assume a device is coming back from a renter or an employee and is going to a new user or a resale channel. The order below is not stylistic; each step depends on the previous one still being available.
Do this before anything else, because of the 15-day window on the device-generated code. If the codes were never fetched, the later steps get harder: you are down to the account holder's credentials or a proof-of-ownership request to Apple, which is measured in weeks rather than minutes. Pass criterion: both codes stored and backed up, associated with the serial number.
Have the user sign out of the Apple Account and turn off Find My, or clear Activation Lock through the management service using the bypass code. Do this before erasing. If you erase first, the device reboots into the Activation Lock screen and you no longer have the user's cooperation guaranteed. Pass criterion: the device can be erased and re-activated without prompting for the previous Apple Account.
Issue the remote erase and record the command acknowledgement. From a data protection standpoint this is not optional tidy-up: once the rental or employment relationship has ended, continuing to hold the individual's personal data is retention beyond what is necessary. Pass criterion: an erase acknowledgement with a timestamp, filed against the serial number.
Unmanage the device and remove profiles and restrictions. This must happen before the ABM record is touched. Once the serial number is unassigned or transferred in ABM, the MDM server loses its channel to that device and any remaining configuration can no longer be revoked remotely. Pass criterion: the MDM console shows no active management for that serial number.
Unassign it from the current management service, or transfer it to the receiving organisation and have them accept. Skipping this step is the most common cause of the classic second-hand failure: the selling organisation sees the device as unmanaged, but on the next activation the device is redirected to the original MDM server, and to the buyer it behaves as a bricked unit. Pass criterion: the serial number shows as unassigned or as accepted by the receiving party. Note that acceptance is time-bounded - if the transfer is not accepted in time it is cancelled and has to be re-initiated.
Keep four items together: settlement date and amount, erase acknowledgement, who released the ABM record and when, and a snapshot of serial number state afterwards. Pass criterion: any settled device can produce those four records within five minutes. Without them, a dispute about residual supervision or about data handling becomes a matter of recollection.
Perform a full erase and take the device through Setup Assistant. If it completes without being redirected to a management server, and without any remote management step appearing, the supervision relationship is gone. If a Remote Management pane appears, or the device name reverts to an organisation's naming convention, it is not gone. This test works because it interrogates the server-side record rather than anything stored on the device.
Complete the release sequence within 24 to 72 hours of settlement. Three things degrade while you wait. The serial number keeps occupying your ABM record, which affects how new devices can be assigned. The device remains registered to your organisation, so if it is lost, damaged or misused in the interval, the evidential burden starts with you. And the receiving party cannot enrol it, which turns a delay into a commercial dispute.
There is a second reason, which is data protection rather than logistics. Settlement ends the relationship that justified holding the individual's personal data in the first place. Binding the erase and release steps to the settlement event - rather than relying on someone to remember - is the cheapest control available, and it is why LuckyMDM (Sichuan Starlight Network LLC) chains settlement, erase and ABM release into one workflow instead of three separate screens.
No. An erase removes local data only. Activation Lock is recorded against an Apple Account and supervision lock against a serial number, both on Apple's servers. Neither is touched by an erase; both need the release sequence above.
Remove it from the MDM server first. Unassigning in ABM withdraws the management channel, after which profiles and restrictions can no longer be revoked remotely - you would have to re-enrol the device to undo anything left behind.
The device-generated code is retrievable for up to 15 days after the device is first supervised, or until the management service explicitly fetches it, after which it is cleared. Practically, fetch and escrow it during initial provisioning rather than relying on the window.
Check in this order: was the previous Apple Account signed out, was the MDM configuration removed, and was the serial number released in ABM. In practice the third one is the usual culprit, because the selling side sees the device as unmanaged and assumes the job is done.
Two. Apple requires the management service to store both the device-generated code and the code its own server creates when it initiates Activation Lock, and to try the other if the first fails. Also note that clearing Activation Lock on a dual-SIM device requires both IMEI values in the request.