Two Locks on One iPhone: Activation Lock vs. MDM Supervision Lock

Published 2026-09-07 · LuckyMDM Blog

Start with the conclusion: an iPhone can be locked twice, by two systems that have nothing to do with each other, and confusing them is the single most common cause of a failed trade-in or a device that will not re-enrol. Activation Lock is a user-level theft deterrent tied to an Apple Account. MDM supervision lock - often called configuration lock - is an organisation-level asset control tied to the device serial number in Apple Business Manager or Apple School Manager. One is stored against an account, the other against a serial number. An erase clears neither, and they are released in a specific order.

1. Two locks, two owners, two registers

Activation LockMDM supervision lock (configuration lock)
PurposeTheft deterrenceAsset control and enrolment enforcement
Created byFind My being turned on by the userDevice serial number assigned to an MDM server in ABM/ASM, via Automated Device Enrollment
Keyed toThe user's Apple AccountThe device serial number, on Apple's servers
Survives an eraseYesYes
Who can release itThe account holder, or the organisation via a bypass code, or Apple with proof of ownershipThe organisation that owns the ABM record
Where it is checkedApple activation servers during Setup AssistantApple activation servers during Setup Assistant, which redirect the device to the assigned MDM server

The third row is the one that matters operationally. Because the supervision record is keyed to a serial number and held on Apple's servers, a device can be erased, restored and re-activated as many times as you like and it will still be pulled back to the same MDM server. Local data can be wiped; a server-side record cannot. This is what makes supervision lock the control that survives in a rental or fleet context, and it is also what makes it easy to leave behind by accident.

2. What Apple's own documentation says about Activation Lock

Several details are widely misreported, so it is worth stating what the documentation actually says:

3. Release order: why the sequence is fixed

Assume a device is coming back from a renter or an employee and is going to a new user or a resale channel. The order below is not stylistic; each step depends on the previous one still being available.

Step 1 - Retrieve and escrow the bypass codes first

Do this before anything else, because of the 15-day window on the device-generated code. If the codes were never fetched, the later steps get harder: you are down to the account holder's credentials or a proof-of-ownership request to Apple, which is measured in weeks rather than minutes. Pass criterion: both codes stored and backed up, associated with the serial number.

Step 2 - Clear the user-level lock

Have the user sign out of the Apple Account and turn off Find My, or clear Activation Lock through the management service using the bypass code. Do this before erasing. If you erase first, the device reboots into the Activation Lock screen and you no longer have the user's cooperation guaranteed. Pass criterion: the device can be erased and re-activated without prompting for the previous Apple Account.

Step 3 - Erase and capture the acknowledgement

Issue the remote erase and record the command acknowledgement. From a data protection standpoint this is not optional tidy-up: once the rental or employment relationship has ended, continuing to hold the individual's personal data is retention beyond what is necessary. Pass criterion: an erase acknowledgement with a timestamp, filed against the serial number.

Step 4 - Remove the device from the MDM server

Unmanage the device and remove profiles and restrictions. This must happen before the ABM record is touched. Once the serial number is unassigned or transferred in ABM, the MDM server loses its channel to that device and any remaining configuration can no longer be revoked remotely. Pass criterion: the MDM console shows no active management for that serial number.

Step 5 - Release the serial number in Apple Business Manager

Unassign it from the current management service, or transfer it to the receiving organisation and have them accept. Skipping this step is the most common cause of the classic second-hand failure: the selling organisation sees the device as unmanaged, but on the next activation the device is redirected to the original MDM server, and to the buyer it behaves as a bricked unit. Pass criterion: the serial number shows as unassigned or as accepted by the receiving party. Note that acceptance is time-bounded - if the transfer is not accepted in time it is cancelled and has to be re-initiated.

Step 6 - Archive the evidence

Keep four items together: settlement date and amount, erase acknowledgement, who released the ABM record and when, and a snapshot of serial number state afterwards. Pass criterion: any settled device can produce those four records within five minutes. Without them, a dispute about residual supervision or about data handling becomes a matter of recollection.

4. How to verify the device is genuinely clean

The only reliable test: erase and re-activate

Perform a full erase and take the device through Setup Assistant. If it completes without being redirected to a management server, and without any remote management step appearing, the supervision relationship is gone. If a Remote Management pane appears, or the device name reverts to an organisation's naming convention, it is not gone. This test works because it interrogates the server-side record rather than anything stored on the device.

Two signals that are not reliable

5. Timing: why release should not wait

Complete the release sequence within 24 to 72 hours of settlement. Three things degrade while you wait. The serial number keeps occupying your ABM record, which affects how new devices can be assigned. The device remains registered to your organisation, so if it is lost, damaged or misused in the interval, the evidential burden starts with you. And the receiving party cannot enrol it, which turns a delay into a commercial dispute.

There is a second reason, which is data protection rather than logistics. Settlement ends the relationship that justified holding the individual's personal data in the first place. Binding the erase and release steps to the settlement event - rather than relying on someone to remember - is the cheapest control available, and it is why LuckyMDM (Sichuan Starlight Network LLC) chains settlement, erase and ABM release into one workflow instead of three separate screens.

Frequently asked questions

Is wiping the device enough to return it to service?

No. An erase removes local data only. Activation Lock is recorded against an Apple Account and supervision lock against a serial number, both on Apple's servers. Neither is touched by an erase; both need the release sequence above.

Should I remove the device from the MDM server or unassign it in ABM first?

Remove it from the MDM server first. Unassigning in ABM withdraws the management channel, after which profiles and restrictions can no longer be revoked remotely - you would have to re-enrol the device to undo anything left behind.

How long do I have to collect an Activation Lock bypass code?

The device-generated code is retrievable for up to 15 days after the device is first supervised, or until the management service explicitly fetches it, after which it is cleared. Practically, fetch and escrow it during initial provisioning rather than relying on the window.

A buyer says the device will not activate. What is the likely cause?

Check in this order: was the previous Apple Account signed out, was the MDM configuration removed, and was the serial number released in ABM. In practice the third one is the usual culprit, because the selling side sees the device as unmanaged and assumes the job is done.

Do I need one bypass code or two?

Two. Apple requires the management service to store both the device-generated code and the code its own server creates when it initiates Activation Lock, and to try the other if the first fails. Also note that clearing Activation Lock on a dual-SIM device requires both IMEI values in the request.

All Articles