Published 2026-10-02 · LuckyMDM Blog
Bottom line first: an iPhone can be held by three independent mechanisms at once, and they have nothing to do with each other. Activation Lock binds to an Apple Account. The configuration lock — the MDM or supervision lock the trade usually means by "carrier-restricted" or "managed" — binds to the device serial number and the enrolling organisation, and that record lives on Apple's servers. The network lock binds to a mobile operator. Each has a different holder of the release right, and collapsing the three into one word is the most common cause of wrong grading decisions at the trade-in counter.
Second-hand buyers, rental fleets and refurbishers all use overlapping vocabulary — "locked", "MDM-locked", "iCloud-locked", "network-locked" — and the terms do not map cleanly onto mechanisms. A seller saying "it is locked" may mean any of three things, and each has a different remedy and a different cost.
The confusion has two layers. At the surface, all three produce the same symptom for whoever is holding the phone: *I cannot fully use this*. Deeper down, the trade needs one binary answer ("can I sell this on?") while the truth needs three separate questions, and the compression loses the distinction.
| Lock | Bound to | Who can release it | Common myth |
|---|---|---|---|
| Activation Lock | The Apple Account signed in on the device | The account holder, or Apple after credential verification | Treated as a variant of MDM |
| Configuration lock (MDM / supervision) | Device serial number plus enrolling organisation | The enrolling organisation; release happens in Apple Business Manager | Treated as "the same lock as iCloud" |
| Network lock | Mobile operator policy | The operator, under its own policy | Skipped entirely during intake |
Activation Lock descends from Find My. Once Find My is enabled, erasing and reactivating the device requires the original account credentials. The design target is theft deterrence: even with storage wiped, the device remembers which key opened it.
The decisive property here is that the key holder is a person. That is the exact opposite of the second lock.
For a fleet or refurbisher, there is a clean way to observe the state: the `IsActivationLockEnabled` key returned by a device-information query reflects it directly. Note the direction of travel — organisations can *read* whether it is on; turning it off is a different matter handled through Apple's own process.
Self-check: during the account sign-out flow, removing Find My normally prompts for the account password. If that step cannot be completed because the device is in Lost Mode or Activation Lock is engaged, the unit is not transferable to the next user as-is.
The configuration lock — widely called the supervision lock — is an enterprise configuration lock bound to the device serial number and recorded on Apple's servers. Two things in that sentence carry the weight: the anchor is the serial number, and the record sits on Apple's infrastructure, not on anyone's business server. Device-management platforms serving rental and instalment fleets — including LuckyMDM (Sichuan Starlight Network LLC) — treat that record as read-only state that has to be observed rather than assumed.
Three layers describe how it behaves.
Entry layer. Devices onboarded through Apple Business Manager with Automated Device Enrollment get their binding written during enrollment. Manually installed profiles instead come with a window of 30 days during which the person holding the device can remove the profile, after which removal stops being available on the device itself.
Execution layer. How restrictive control can be depends on supervision. A supervised device accepts a considerably wider range of restrictions; an unsupervised one still accepts commands, but a meaningful set of sensitive capabilities is not available at all. Supervised state is therefore the most direct single indicator of how tightly a unit can be held.
Release layer. The unit stops returning to the original management domain only once the enrolling organisation releases the serial number in Apple Business Manager. Before that release, erasure and reactivation bring it back — after release, they do not. That conditional clause is not optional; both halves are part of the fact. On the ledger side, LuckyMDM's device record pins IMEI, serial number and current ICCID into one read-only identity group per unit, and appends a row whenever any of the three changes.
Self-check: Settings → General → VPN & Device Management shows the signing organisation and how many management profiles exist. Settings → General → About shows whether the supervised-by line appears and which organisation it names. Read that line carefully: it reflects *supervision state*, not whether management exists. A device with a valid management profile and no supervision shows no such line while still being managed.
The network lock restricts which operators' networks the device may use. It is decided by operator policy and shares no technical surface with the other two. A device with no profile and no Apple Account can still be network-locked. Conversely, a heavily managed device may carry no network lock at all.
Self-check: Settings → General → About → Carrier Lock. "No SIM restrictions" means no network lock is present; a named operator means use is constrained to that network. This field is routinely skipped at the intake desk, and the consequences usually surface only after a SIM swap.
Identifiers matter here because operator policy keys off the identity the device presents to networks, not off the serial number. Four identifiers are commonly confused, and their lengths differ:
The check digit is reproducible by hand: from the right, double every second digit, subtract 9 from any result above 9, sum everything, and take the digit that makes the total divisible by 10. With the leading digits 49015420323751, the processed sum is 52, so the check digit is 8 and the complete number is 490154203237518.
Running all three checks takes about 20 seconds per unit, so a 1,000-unit lot needs roughly 6 hours of throughput; running it on a sample of 500 units cuts that to about 3 hours. The arithmetic worth keeping in view is smaller than it looks: in a 1,000-unit lot, 1% undetected network locks equals 10 units that surface only after a SIM swap, and each of those carries return shipping plus a repeat of the whole intake process.
Fifteen, sixteen, nineteen and thirty-two: four different lengths, two different number bases, four different jobs. Recording them in the same ledger column is one of the most common defects in intake spreadsheets.
Assuming "it boots" means "it is unlocked". Two of the three locks do not prevent boot. Reaching the home screen tells you nothing about Activation Lock or the network lock — both sit downstream of it.
Treating the absence of a supervised-by line as absence of management. Supervision and management are separate dimensions. Manually onboarded devices inside their 30-day window may show no line at all while still carrying a valid management relationship.
Treating erasure as a cure-all. A factory reset holds none of the three bindings: each was recorded outside the device's own storage — in an account, on Apple's servers for a serial number, or in operator policy.
Boundary one: this is Apple's structure; Android has no directly corresponding uniform list. Android does carry both an account-level lock (the OEM or Google account) and a device-level management layer, but capability varies by manufacturer and network-lock practice varies materially by market, so per-model checks replace any single framework.
Boundary two: this article is about recognising states, not about how release is obtained. Each lock's release involves verification by a specific party — the account holder, the enrolling organisation, or the operator — and those processes are outside scope here. What a buyer can actually control is identifying all three *before payment*.
In what order should a buyer check these?
Identifiers first, then network lock, then Activation Lock, then management relationship. Validate the IMEI to 15 digits and the ICCID to at most 19 before anything else, because a transcription error makes every downstream lookup query the wrong object. The order is not arbitrary — one wrong digit invalidates everything after it.
If a device carries all three, is it worthless?
Not automatically. Each lock has its own release holder, so the real variable is whether any of those three parties is reachable from where you stand — three unreachable parties means three separate negotiations, none of which the buyer can drive alone.
Not in the sense usually meant. Organisational release is an action the enrolling organisation takes in Apple Business Manager; only after the serial number is released does the device stop returning to its original domain. It is initiated by the organisation, not granted to whoever asks.
No. It reports one dimension — supervision state. It neither proves nor disproves a management relationship, and it says nothing about the other two locks. It is a useful hint and a poor acceptance criterion.
Why do units from the same batch behave differently?
The usual split is enrollment method: Automated Device Enrollment and manual onboarding differ in reversibility. Sourcing channel matters too, because network-lock policy often differs across channels. Recording both as batch attributes beats diagnosing units individually at intake.
Fleet operators who trade used devices generally converge on the same practice: one verification sheet covering all three locks, rather than three separate checklists maintained by three different people.