Skip to main content

iOS 13 Unlock Token Handling (Historical)

FileWave'sHistorical compatibility note. This page documents iOS 13 unlock-token handling in FileWave 13.1.2 and earlier. Use a currently supported FileWave release for production device management.

FileWave MDM solutioncan hasclear the ability to unlock devices which area passcode protected.on Thisa canmanaged be very useful to recover devicesdevice without an administrator knowing the passcode set by studentsthe user. This is useful when recovering shared or users.institution-owned devices.

To achieve this, theThe device sends FileWave an Unlock Token,. whichFileWave isreturns thenthat sent back to the devicetoken with the ClearPasscode request.request, This ensures security as onlyso the enrolled MDM solutionservice wherecan clear the devicepasscode iswithout enrolled can unlockreceiving the devicepasscode - and access to user data.itself.

MovingIn forwardiOS with security,13, Apple changed how this unlock-token isdelivery sentso to MDMs in iOS 13:that the token is sent only once during enrollmentenrollment. ;Protect thereforethe it's extremely important to keep thisstored token safe.and include FileWave data in the organization's backup plan.

Apple recently clarified how this change would be effective: the device may still send a TokenUpdate message to the MDM server, but the message will not contain the token anymore.

UntilBefore FileWave 13.1.3, sucha aTokenUpdate message (TokenUpdate without UnlockToken)an wasUnlockToken consideredcould to be a message clearingclear the token ;stored thereforeby managingFileWave. Managing iOS 13 devices with aan previous version can leadearlier FileWave torelease clearcould storedtherefore tokensremove andthe thenserver's not being ableability to clear the device passcode.

It is therefore highly recommended to:

  • regularlyBack backupup yourthe FileWave instance,instance toregularly keepso sensitive datadata, likeincluding unlock tokenstokens, inis a safe placeprotected.
  • upgrade toUpgrade FileWave 13.1.32 ifor you planearlier to upgradeat yourleast devices13.1.3 tobefore managing iOS 13 devices.
  • ensureEnsure iCloud backupBackup is configured on iOS devices when it is permitted by organizational policy.

You also have the ability to defer software updates by deploying a restriction profile (more information in this KB article)