Got a tip for us?

Security

Avoiding malware is a result of both preparation and ongoing vigilance and consistent behavior.

Apple’s built-in protections

Early in macOS’s history, Apple took a hands-off approach to malware, working to keep the system as free of exploits as possible, but leaving viral issues to third parties. That changed in Mac OS X 10.6 Snow Leopard, when Apple added the first vestiges of XProtect, its file quarantine and anti-malware checker. It now has several often interlocking measures.

Like Gatekeeper, you won’t find the name XProtect in macOS at all; Apple describes it only on their website.

Apple continues to add invisible and overt protections, too, such as the anti-paste warning and script blocker described in the kinds of Mac malware.

XProtect and XProtect Remediator

XProtect offers just a single aspect of anti-malware software, which is that it protects against known exploits. Using a method that relies on a signature that identifies specific malware, XProtect from macOS 10.15 Catalina onward checks apps when first launched or after they’ve been modified, and whenever the list of signatures updates. Apple collects these signatures into a database; a scheduled process automatically checks every 24 hours for updates to it. Apple will make emergency pushes to your Mac sooner if necessary. If a compromised app is found, you’re alerted to take action.

The moment an exploit is found in the wild, these XProtect updates ensure no Mac user connected to the internet after that point will be subject to the attack, even as Apple releases operating system security software fixes that take longer typically to ship that prevent future variant attacks that rely on the same weakness.

Apple used to also schedule regular passes by the hidden Malware Removal Tool (MRT), which could both find and remove malware, including in documents. Because Apple provides only limited documentation about XProtect and didn’t even mention MRT, it’s hard to know how they interact. Fortunately, Mac users have the previously mentioned Howard Oakley, one of the key independent people who finds and documents hidden system-level features.

Howard discovered Apple had added a new tool called XProtect Remediator that runs frequently and can both discover and remediate (take action on) any malware it finds. Howard reported in 2022 that Apple sunsetted MRT and now relies entirely on Remediator—including in macOS back to Catalina—which scans about once a day generally, although individual modules may run more frequently. In a post in June 2023, Howard explained the replacement and listed current modules that Remediator uses to check for known malware.

Check Howard’s site for updates about XProtect and Remediator if that piques your interest. Or get his free tool, SilentKnight, to get detailed information about scans and fixes installed on your Mac.

Gatekeeper

Gatekeeper is a great way to prevent potentially dangerous software from launching, even when you’ve been fooled into downloading a file you think is legitimate. Likewise, configuring Gatekeeper to App Store only for accounts you manage for other people—kids and others who want you to help them stay out of trouble—limits their potential exposure even more.

System extensions

The macOS system can be modified by extensions, as covered in what launches on your Mac, which includes modifications to and monitoring of network traffic. Even third-party software that’s notarized and signed has to declare to Apple what kind of networking it’s engaged in. Thus, a virus that somehow managed to insert itself into legitimate, signed software would still be unable to tap into your networked data without alerting you or causing errors.

Security responses

Starting in macOS 13 Ventura (and iOS 16/iPadOS 16), Apple added Rapid Security Response, a new method for delivering critical security updates without requiring a full system update. Starting in Golden Gate, macOS seemed to encompass those responses in the “Install system data files and security updates” setting in Automatic Updates; see how to set up automatic security updates. All the items in this category are installed automatically and don’t require a reboot.

Apple’s array of protections, described in how macOS protects its own system files, prevents malware from changing them.

Keep good backups

The easiest way to fight malware of all kinds, and particularly ransomware, is to have a continuously streaming backup of your documents, along with an archive or version history.

Ransomware attacks occur at some specific point in time, and most of them aren’t subtle: they try to encrypt all potential files as fast as possible to avoid detection. While some malware can try to erase backups or you might discover it was installed months ago, ransomware requires a much shallower archive.

If you have any or all of the following, you can use anti-malware software to remove the ransomware; tune up your system to avoid future attacks; and then restore files:

  • Time Machine: Time Machine backups retain file versions as they’re modified, and updates are typically written every hour. Older files are typically deleted only after a few weeks and only when there’s pressure on available storage. You may be able to roll back your corrupted files to a snapshot just before the attack began.
  • Cloud backups: Backblaze and other incremental archiving services typically run continuously or frequently, and retain overwritten and deleted files for a period of time, usually no less than 30 days. Some services let you pay extra to retain files for up to one year or as long as forever—as long as you keep paying. Using the service’s tools, you can find the point before the attack and download an archive of pristine files.
  • Sync services: Services like Dropbox and others sync files as you modify them while retaining previous versions and deleted files, just like cloud backups. It can be a little trickier to grab all files from a point in time, but it’s doable.
  • Occasional offline clones: Obviously, if you clone your drive after a ransomware attack, the cloned version has the same problem as your live system. However, making regular clones that you store offline (not connected or powered up), or even offsite, can give you a revert position if you have a problem with other backups, even if you might lose some more recent file changes or email messages.

Backblaze stopped archiving cloud-based files available through the macOS filesystem, such as Dropbox, Google Drive, and Microsoft OneDrive, in April 2026. Some people were upset about this, because Backblaze provided this detail in an update log for its apps rather than in an announcement. It’s not in a support note, either.

The reason, however, is straightforward: Apple shifted how cloud sync services appear in macOS to the Finder, apps, and parts of the system. The files appear locally stored, while sync service components ensure they load a file on demand if there’s no cached copy.

For backup services, that’s problematic, because it either means every synced file is loaded, which causes delays and huge bandwidth usage, or a stub is stored, which isn’t useful for restoring. Backblaze opted out, since it can’t reliably ensure it’s copying your cloud files.

So what are you to do as a user? The reason to use the cloud is to not store files locally. I don’t want to—and don’t want you to—rely on the potential that just a single copy of your files exists in the cloud. I haven’t figured out the answer yet. Carbon Copy Cloner and other tools have a way you can temporarily download files from the cloud to back them up, but there are complications involved in this, too, as Bombich Software explains in a detailed note for CCC.

Common sense

As with everything in the world of security, all you can do is improve your odds. So, when it comes to malware, here are my recommendations. First, everyone (regardless of risk level) should do the following:

  • Install security updates rapidly: Apple pushes XProtect Remediator updates to your Mac and Rapid Security Responses, but you need to choose to install or set automatic installation for most security updates. Apple will often put out the word if there’s a really severe problem. See how to set up automatic security updates.
  • Trust your gut when it says “no”: If you receive an email that wants you to carry out an action, give it a few looks before proceeding. Don’t click unknown URLs. If you reach a site with a weird or dubious URL, close the tab immediately. Don’t enter your administrator password when you don’t know why it’s being asked.

I’m not waggling my finger at you—I’ve missed my gut talking, too. Recently, a spate of “unpaid toll camera fee” and “unpaid traffic ticket penalty” texts spewed in my and many people’s text messages. Since we have a toll bridge near us, I thought, “Oh, something must have gone wrong with the account.” But I checked the account first instead of clicking the link. That saved me.

Apple and third-party password managers keep you from falling into a phishing abyss. If you saved a password or passkey at americanexpress.com and go to amer1canexpr3ss.com, the manager won’t cough up the credentials. Keep a close eye on this, as sometimes companies have multiple sites for different services or tasks, and you may occasionally have to use your credentials at a different domain.

  • Filter your mail: Email is one of the most common ways for malware to spread, and a good spam filter will zap it before it hits your inbox—or before you’re as naïve as I am sometimes!

Even if your email provider offers effective, configurable server-side filtering, I recommend adding SpamSieve.

  • Avoid software whose origins you don’t know: Malware often spreads through sketchy or pirated software. If you don’t know who made an app or where it came from, or you know it should be paid for, but you’re nevertheless downloading a cracked or otherwise non-legitimate version, you are asking for trouble.

Firewalls and network monitoring

At one point we both avidly recommended using firewall software. Apple’s built-in solution is fairly weak, so we’d suggest one of several third-party options, often bundled with anti-malware software. Up until a few years ago, it seemed like the biggest risk to a Mac user would be from a remote invader.

Turns out, not! Phishing, Trojan horses, stolen or misused developer certificates, and simple “hey, install this by typing in your administrator password” were the big vectors—and not very big at that.

As covered in which Mac sharing services are safe to turn on, the best advice is to not enable network services you don’t need.

Apple built in privacy protection for an issue adjacent to your IP address. Every Ethernet or Wi-Fi adapter, built in or plugged in, has a unique MAC address—that’s Media Access Control, not Macintosh. A MAC address appears in the form xx:xx:xx:xx:xx:xx, where each x is a value between 0 and 15 expressed in hexadecimal (0 to 9 then A to F). Apple perplexingly calls it a “Wi-Fi address”, which is the incorrect name.

A MAC address is how a device communicates over a local network, used to make sure every interface has a unique address to avoid data being delivered to the wrong location. However, because this MAC address is set in hardware, clever hackers and marketers started to use it to associate people with devices—your MAC address persisted indefinitely, so a Wi-Fi router in a public place could conceivably track you over time whenever you connected to any router that shared information with a central database, like a cell carrier or ad-targeting service. Bad!

Apple got around this by adding a “Private Wi-Fi address” option (still the wrong term) that generates a unique MAC address for each Wi-Fi network you join, changing it from time to time. This deters and potentially fully prevents MAC-based tracking.

Apple made significant changes to this several-year-old feature in iOS 18/iPadOS 18, macOS 15 Sequoia, and watchOS 11.

You can configure “Private Wi-Fi address” in one of three ways:

  • Off: The actual unique MAC address is sent to the router.
  • Fixed: Your device generates a MAC address that’s used consistently for the selected Wi-Fi network. This may be required in some places in which a MAC address is used as part of a hotspot portal’s permission system that grants you access or in corporate environments when you’re a guest. Your home router may even offer an option to set a fixed private IP address using a MAC address, so your MAC address needs to be fixed.
  • Rotating: The private address that’s generated is changed to a new, randomly created one every two weeks, whether you’re connecting in that period or after a gap of two weeks or longer.

Apple defaults to either Fixed or Rotating. It uses Fixed the first time you connect to a network with relatively modern Wi-Fi network security—WPA2 or later, to use the technical term. A network without such security, either using outdated standards or requiring no passwords, such as at an open Wi-Fi network at a café, is set to Rotating by default. You have to choose Off, read a warning, and confirm.

The options to change the type of Private Wi-Fi Address used with a network vary by operating system:

  • iPhone/iPad: Go to Settings > Wi-Fi: tap the info button next to the currently connected network or any other network that appears. You can also tap Edit, and then tap the info button next to any stored network.
  • Mac: Go to System Settings > Wi-Fi > Details for the active network. For other networks, click the More button; for Known Networks, then choose Network Settings.

To see the underlying Wi-Fi adapter’s hardware-set MAC address, go to Settings > General > About and look for Wi-Fi Address on an iPhone or iPad. On a Mac, follow the path of System Settings > Wi-Fi, click the Advanced button, and see Wi-Fi MAC Address near the top.

It is rare to find an app that hasn’t gone through notarization. But you may still encounter software you can download from an open source project’s site—typically free and often developed by a group of volunteers—that isn’t signed and notarized.

While most developers consider Apple’s annual developer program fee and company oversight affordable and reasonable, some folks do not. They may be creating a small piece of utility software that’s maintained, but nobody in the group that produces it wants to either ask for donations or cough up the dough. Or they may find Apple’s oversight irksome and invasive, despite the advantage to users. Or they may have interpreted copyright in a way that doesn’t match Apple’s policies.

If it’s not the above case, there are a few other reasons that you might encounter an app Gatekeeper balks at:

  • You run a preliminary version of a new app that the developer simply hasn’t gotten around to signing yet.
  • You create your own app or standalone script (perhaps using Script Editor) and don’t want to (or don’t know how to) sign it.
  • You’ve downloaded malware. It isn’t signed because the developer doesn’t want to risk exposing their identity—and enabling Apple to revoke the certificate, thus preventing the app from being installed in the future.

Whatever the reason, if you launch an app that isn’t signed or is signed but not notarized, macOS explains the problem. The dialog may say that it’s by an unidentified developer, or by a developer whose identity can’t be verified. Click OK—the only choice—and the app never completes launching.

Apple does let you install Mac software like this, but they don’t make it easy. There used to be an option in the Gatekeeper settings to disable Gatekeeper altogether; now, you have to use a manual bypass for any such app you want to launch on its first use, which Apple made more complicated in Sequoia to deter people even further.

Before you override Gatekeeper, give a lot of thought to what you’re trying to run and where you got it. As battle-scarred and cynical as I am, I always take additional effort and make additional scrutiny before bypassing Gatekeeper for an app I know I need and know its source.

Check it before you run it

The most excellent developers who forswear Apple’s process always offer out-of-band methods you can use to check the integrity of their downloads. So if you trust the project and want to make sure an app hasn’t been fiddled with, the site might post hashes it makes of its disk image files at the time of creation, or use its own signing process that can be validated with publicly available encryption keys. The best of these apps will then also provide pointers on how to perform validation and authentication without you having to take a two-hour cryptography course.

With all that in mind, here’s how to bypass Gatekeeper.

  1. Open the application. You see a dialog saying the app can’t be opened, with no suggestion of what to do next. Click Done.
  2. Go to System Settings > Privacy & Security. As with a signed app when you have Gatekeeper set to App Store, you have identical text and an Open Anyway button.
  3. Click Open Anyway.

I’m not sure Apple made the right call here, equating signed apps from developers and unsigned apps as the same kind of problematic item based on the Gatekeeper setting. But I suppose both are now considered suspect in the context of each setting choice.

Your Mac has a low-level secret-managing system called Keychain, which is covered more fully in where Apple stores your passwords and passkeys. Keychain contains passwords for lots of different things that need to be both available on demand and secured against unauthorized access. This includes passwords to log in to apps and Wi-Fi networks, passkeys for websites at which you’ve enrolled to use them, credentials for local network servers, encryption certificates, and other important information your Mac needs to function securely.

If you sync Passwords with iCloud, Keychain also contains credentials for websites where you have accounts and may include your credit card details, separate from the stored Apple Pay payment card information on Macs with Touch ID or an Apple silicon Mac paired with a Magic Keyboard with Touch ID.

Because this information is valuable and potentially sensitive, a Mac encrypts the contents of your keychain. However, whenever your Keychain is unlocked, your credentials can be passed to apps, websites, and network services without any intervention on your part.

And how do you unlock your keychain? That’s the wild part: all you have to do is log in to your Mac’s user account. And—as covered in what launches on your Mac—another default setting is to log you in to your account automatically.

As noted earlier, if you have FileVault enabled, you can’t log in automatically. However, after you manually log in, you’re in the same boat as anyone else. See how to turn on FileVault.

In other words, unless you take steps to change the defaults, merely turning on your Mac might unlock your keychain!

Anyone else who might have physical access to your Mac could then log in to all your web accounts (like your bank, Amazon, or PayPal), file servers, and other resources where you’ve saved credentials (like Music or the App Store).

There are a few bright spots:

  • No one can see the actual keychain entry’s secure text without knowing your macOS account login password.
  • Within Safari, an unwanted party can’t get a list of all the sites at which you have passwords stored from Safari, Keychain, or the Passwords app without your password.
  • Even when a password is autofilled in Safari or in an app, there’s typically no way to copy the password to view it as text.
  • Macs with active Touch ID hardware and password autofill enabled will drop in your password only when you use a valid fingerprint or enter your password (System Settings > Touch ID & Password > “Use Touch ID for autofilling passwords”).

Touch ID can be built in, as with a laptop model, or for an Apple silicon Mac, provided via a paired Magic Keyboard with Touch ID. See how to set up Touch ID and Face ID.

Yet the storm cloud lingers: someone can use all your passwords when the conditions above aren’t true. These actions will help prevent that:

  • Leave FileVault enabled: Because FileVault is a high-value way to prevent power-up access to your computer, most people should leave it enabled, and it is on by default starting in macOS 26. Some people may find it more trouble than the potential of losing access to their files; see how to turn on FileVault for both sides.
  • Turn off automatic login, if you don’t have FileVault enabled: See what launches on your Mac for how to disable it.
  • Enable Touch ID and AutoFill: This blocks access to autofilled passwords without your fingerprint or password.
  • Lock your Mac after a duration: See the Mac settings worth changing.

Lock the keychain separately

For most people, setting their Mac to lock when it sleeps, when the display is off, or after a screen-saver duration has passed, as described in the Mac settings worth changing, is enough. But macOS also lets you lock the keychain after a set period, even if your Mac remains unlocked.

First, open Keychain Access, located at /System/Library/CoreServices/Applications. Click Open Keychain Access at the prompt.

Select your login keychain, and choose Edit > Change Settings for Keychain “login”. You can select “Lock after X minutes of inactivity,” pick a time delay, and click Save. (The “Lock when sleeping” option makes little sense—you should set your Mac to lock when sleeping, as that locks the Keychain and your session.)

Note that you can only change settings for the login keychain and your custom keychains, if any. You cannot change these settings for the System, System Roots, or iCloud (if enabled).

The basic idea of a sandbox is that an app has restrictions that define where it can read and write data, as well as the kinds of inputs and outputs it can monitor or make use of. It has to “keep its sand in the sandbox”: it can’t see or touch files anywhere outside its designated space, or listen to mics, view video, or capture keystrokes without explicit permission that you give it when prompted or that you configure to allow.

Apple rarely uses the term sandboxing in end-user materials, though they employ the concept all over.

The intention is to prevent buggy, corrupted, or malicious apps from messing with data and files from other apps or macOS itself. It has the additional benefit of limiting legitimate software from accessing personal information and inputs that you don’t think it needs to.

There are three kinds of sandboxing in macOS. The oldest affects apps as a whole.

App sandboxing

Available since Mac OS X 10.7.5 Lion, macOS’s app sandboxing restricts the kind of behavior apps can engage in outside their bounds—particularly their own set of data and caches.

Suppose you visit a rogue website in Safari that attempts to execute some dastardly code through an exploit someone has discovered in JavaScript, the popular programming language that powers web apps. Because Safari runs in a sandbox, that malicious code can’t affect other files: it can’t read your contacts, delete system files, add a startup item, or do any other mischief outside the browser window without your permission.

System files are additionally protected in yet another kind of sandbox. See how macOS protects its own system files.

Apps downloaded from the Mac App Store must be sandboxed (with some exceptions for older apps). In addition, Apple apps included with macOS are sandboxed, and so are many third-party apps available directly from their developers. (That’s usually because they also offer the apps in the App Store and don’t want to create two entirely different versions.)

But nothing in the design of macOS (at least, not yet) prevents you as a user from running a non-sandboxed app if you want to. Unless you get an app from the App Store or the developer tells you the app is sandboxed you have no easy way to know.

Sandboxed apps can read and write files in non-default places if you agree to let them do so. You’re prompted when you try to access a new location, and have to give simple permission: a click, not a password. That’s then remembered by macOS from then on. (Under certain rare circumstances, you might have to reauthorize an app.)

You can’t turn off sandboxing or adjust its settings. All you can really do is be alert—if an app asks for access to a folder you don’t think it should be using, that’s because the folder isn’t currently within its sandbox. Think carefully before saying yes—if it’s unexpected, the app could be trying to do something it shouldn’t.

Camera and microphone permission

Since Mojave, macOS asks you questions when an app or other software tries to use audio input or video cameras for the first time.

This was added to prevent potential snooping by malicious software, by having a deeply wired system opt-in requirement. It’s one thing for a malware developer to hack into your camera through software that runs with user-level permissions; it’s another for them to subvert the system and block the warning.

A lot of security and privacy companies offer A/V input features in their anti-malware software or standalone apps, some with more granularity (like “allow for an hour”) and a different workflow for detection. The free OverSight app from security researcher Patrick Wardle is a great place to start (along with all his other apps).

Apps don’t have to do anything special to request access. If it hasn’t been granted access, the first time an app attempts to use a camera, mic, or other audio input, macOS prompts you to approve it or not. If the app wants to bypass Apple’s built-in system, as with Zoom, you see a more severe warning about what it could access.

Once approved, manage access for apps and other components via System Settings > Privacy & Security. In some cases, deselecting an item results in a prompt to choose to quit and restart the app you changed settings for and offers Later as the other option.

Notebook Macs have a hardware disconnect switch that cuts off mic input when the lid is closed, too.

Some apps may have multiple entries in the list: one is for the user-facing app you launch and another for helper software that runs in the background.

Apps may respond differently if you deselect mic or camera permission. Some may not recognize they lack access and crash or behave erratically. Others test for access and prompt, such as Zoom after I allowed and then disabled camera access.

To let you know when certain inputs are in use, Control Center briefly displays a message showing recent use of your mic or camera. Click to reveal Control Center, and you’ll see a mic or camera icon followed by an app name, sometimes followed by “recently” if it’s active or was just active. The status message disappears quickly.

Any use of video, audio, or screen control/screen sharing lights up a colored icon in the menu bar—a green video icon, an orange mic icon, or a purple screen use icon—that indicates active or recent usage. Click the menu to reveal available specialty options for camera and mic effects, like Studio Light for your video or Voice Isolation for your mic, or to see what app is making use of your screen. (I’ve even seen two screen use icons: one for the Screen Sharing app and one for general screen-recording.)

Folder permission

In addition to app-based and A/V input sandboxing discussed above and personal-data privacy controls discussed just below, Apple uses sandboxing for all apps, which requires your permission for them to access certain folders. These locations include:

  • The Desktop, Documents, and Downloads folders in your account
  • Your iCloud Drive access
  • Cloud storage from third parties that appears via Finder-accessible folders, like Dropbox and Google Drive
  • Network volumes and removable volumes, each as a separate category of permission

The idea is that it’s suspicious if an arbitrary app needed to read from, much less write to, any of these locations without your explicit knowledge and permission. This can also help subvert ransomware, which tries to access important files wherever they are stored.

Whenever an app first tries to access items in any of these locations, your Mac prompts you to ensure you want to allow it.

If you use an external startup drive, you will see this message frequently. Every time an app wants to save a file on the startup volume, a Mac prompts for permission. By design, Apple prevents apps from saving to external volumes without a grant of permission.

As with mic and camera input, you can view and revoke permissions in System Settings > Privacy & Security: select Files and Folders and scroll to find the app.

Once you grant permission, you can only disable it—you can’t remove it from the list. The only way to remove an app from the list is to empty the list entirely using the command-line utility tccutil. It’s rare you would need to do this.

While macOS is a friendly operating system, it’s all Unix under the hood, which means it runs by partitioning access to files and apps by users and groups, selectively providing permission based on who you are and what groups you belong to.

If your Mac has only one user—you!—it’s all very simple, because you don’t need to secure yourself from yourself. However, you still need the following information, as it relates to how you manage a single-user Mac, too.

There are several important principles about user accounts, and how private your files really are covers the other side of the same question:

  • There are four main types of Mac user accounts: administrator, standard, guest user, and sharing-only. Of these, administrator and standard are by far the most common. The usual reason to have more than one account is so that each person who uses a particular Mac can have a separate space for files and settings. But accounts can also be used to restrict access to certain files or resources in order to improve your security.
  • Every Mac needs at least one administrator account. When you set up a new Mac or perform a clean installation of macOS, you’ll be prompted to create an administrator account before you can do anything else. That’s because only administrators can perform certain crucial tasks (see the next bullet point). You can have more than one administrator account, and in fact, it isn’t a bad idea to set up an extra one to use for testing and troubleshooting.

When something fails for me on one account, such as a software app or Safari extension, I often log in to a second administrator account on the same Mac to determine whether it’s a problem with my account or the software—or the whole Mac.

  • Administrator accounts are all-powerful. Administrators can create, modify, and delete other user accounts. They can unlock any pane of System Settings, and authorize any type of software installation. They can (with a quick trip to the Terminal utility) open any file on the Mac, belonging to any user—and can change any non–system file’s permissions. They can upgrade macOS to a new version. The list goes on and on.
  • Standard accounts can do most ordinary things. Standard users can run apps, work with files, and perform most ordinary day-to-day tasks. When a user with a standard account tries to do something that only an administrator is allowed to do, simply entering an administrator’s username and password (or having an administrator do so) does the trick—there’s no need to log out or switch accounts first.
  • Apps get their privileges from the user who opens them. If someone with a standard account launches an app, that app can access only the files and folders available to that user. If someone with an administrator account launches an app, that app has more expansive access to files on the Mac, although sandboxing limits that scope somewhat; see how to control which apps use your Mac camera and files. A malicious or compromised app launched by someone with an administrator account might be able to do serious damage across the Mac.

You can create as many user accounts as you need, and switch between them easily. To keep your Mac secure, you should make sure you have the right number and types of accounts, as below.

Set up a standard account for others

A standard account has permission mostly to affect files and applications installed within the Home > Username folder. It’s the right kind of account to set up for people using a Mac who aren’t sophisticated users, don’t need system-level access or the ability to install apps for all users, or shouldn’t be given the same level of trust on a shared computer as its owner or administrator.

At one point many Mac experts recommended a standard account for day-to-day use even by its main user or owner, and to use the credentials for an administrator account only when you’re installing software or engaged in other tasks that require access to the depths of your system.

However, macOS has changed significantly over the last several years. System files are now locked down and can’t be accidentally deleted or overwritten. Many actions you take require a Touch ID or password confirmation. To be frank: I’ve never used a standard account as my regular login, and I don’t see a reason for anyone else to do so at this juncture, either. (I have great backups that I can fall back on if I do anything epically poorly thought out.)

If your main account is currently an administrator account but you want to make it a standard account, you can create a new administrator account (for occasional use only) and then remove the administrative privileges from your main account.

  1. Go to System Settings > Users & Groups.
  2. Click the Add User button.
  3. Enter your password if prompted.
  4. Choose Administrator from the New User pop-up menu.
  5. Fill in the fields for Full Name and Account Name (that is, a short username, such as your initials). They can be anything you like, but they must be different from those used for other accounts on your Mac. Every account, especially an administrator account, should have a password that is both strong and unique.
  6. Create a strong password and enter it in the Password and Verify fields; optionally enter a password hint.
  7. Click Create User. If you had automatic login enabled, an alert appears, asking if you want to keep it on or turn it off. Click Turn Off Automatic Login. (This won’t appear with FileVault enabled.)
  8. Choose Apple menu > Log Out Username to log out of your old administrator account.
  9. Select or enter the name of the new administrator account you just created, enter its password, and click the arrow button or press Return.
  10. Once again, go to System Settings > Users & Groups.
  11. Click the info button next to the old administrator account, then use the credentials for your new administrator account to authenticate.
  12. Deselect or disable “Allow this user to administer this computer”; this turns your erstwhile administrator account into a standard account. An alert appears, claiming that you must restart for the changes to take effect. That’s not entirely true (you need only log out), but click OK anyway.
  13. Choose Apple menu > Log Out username, then log in to your old account, now a standard one, with your password.

At this point, you may be prompted to enter the Apple Account for the new account. Since this administrator account will be for occasional use only, I suggest selecting the Don’t Sign In radio button, clicking Continue, and then confirming by clicking Skip again. If it turns out you need iCloud services with your new administrator account, you can always set them up later.

Screen Time for a child account

Screen Time is Apple’s cross-device, Apple Account-linked system for monitoring device usage and, for kids and other people one serves as a guardian for, controlling access. You can use Screen Time to track your behavior and set alerts about limits.

Screen Time isn’t strictly a security feature, and Apple overhauled it in the 27 releases; the parental controls are covered separately.

Set up a guest account

As long as you’re making changes in Users & Groups, you should think about whether you want to have a guest user account. It’s enabled by default starting way back in Yosemite. That’s usually a good idea, but if it doesn’t suit your needs, you can disable it.

With a guest user account enabled, you have a spare—and, importantly, non-administrator—account that anyone can log in to without a password. When logged in, they can run apps installed for all users, browse the web, or perform any other task that doesn’t require saving private information to disk permanently. (Guest users can, however, save data to publicly shared locations.)

If you prefer to not have a guest account, you can also restart your computer in recovery mode and choose Safari as an option. This lets a guest use Safari with zero access to locally stored files. See how macOS protects its own system files.

As soon as the guest logs out, macOS deletes the guest’s temporary home folder, leaving everything just as it was beforehand. If you ever need to give someone temporary access to your computer, using the guest account is simpler than having to set up and later delete a conventional account for that person, and more secure than letting them use your account.

If you have FileVault enabled, the Guest user can access only Safari.

  1. Go to System Settings > Users & Groups.
  2. Click the info button to the right of the Guest User entry.
  3. Enter your administrator password if prompted.
  4. Enable or disable “Allow guests to log in to this computer”.

With guest access enabled, you can optionally select either or both of the following checkboxes in the Guest User settings:

  • Limit adult websites: Apple blocks risqué-and-beyond sites.
  • Allow guest users to connect to shared folders: This doesn’t affect the way someone logged in as a guest can access shared folders on this Mac, as you might expect. Rather, when selected, people on other devices on the network can connect to this Mac’s shared folders without supplying a username and password.

Give every user their own account

If you’re the only person who uses your Mac, you can skip this topic. But if you share your Mac with family members, coworkers, or friends, do yourself—and them—a favor and create a separate (standard) account for each person. And then, insist that everyone log in to their user-specific accounts when using the Mac. That way, any damage (accidentally deleted files, changed preferences, and so on) will be restricted to that user’s space and not affect the entire Mac.

To enable switching from one user to another without having to log out (and thus quit all your apps):

  1. Click the Control Center button.
  2. Click Edit Controls.
  3. Enter “fast” in the search field.
  4. Click the Fast User Switching icon.
  5. Choose either Add to Control Center or Add to Menu Bar. You can choose one and then the other.

If you add it to Control Center, you can drag to put it where you want among other controls.

To switch users, access the list of users by clicking the account button, account name, or full name from the menu bar or opening Control Center and clicking the Fast User Switching control. Choose the name of the user you want to log in as. That list also includes Login Window: select it to drop into the Login Window screen.

Biometric protection is a terrific safeguard to layer on top of other basic protections. By letting you use a fingerprint or your face to unlock your device, it increases security for your files and data while also making it easier for you to log in.

Touch ID first appeared on iPhones with the iPhone 5s in 2013, and was added to iPads starting with the iPad Air 2 model the next year. All subsequent iPhones and iPads included Touch ID until Face ID replaced fingerprint authentication on the iPhone starting with the iPhone X in 2017. Since then, it’s been part of every iPhone except the iPhone SE series, which retains Touch ID.

The sole iPad model with Face ID is the iPad Pro, starting with the 1st-generation 11-inch and 3rd-generation 12.9-inch models in 2018. All other iPads that can run iPadOS 26 or 27 have Touch ID, which dates back to 2014 in some iPad model lines.

Touch ID was extended to Mac laptops starting with two 2016 MacBook Pro models. It was later added to all new MacBook Pro models and the MacBook Air starting in 2018, when it became standard. However, that doesn’t help those of us with desktop Macs.

In May 2021, Apple released the Magic Keyboard with Touch ID (in both standard and extended versions) along with their new M1 iMac. This brought Touch ID to a desktop Mac for the first time. Apple later began selling this version of the Magic Keyboard separately, and while the keyboard part works with any Mac, the Touch ID sensor requires an Apple silicon processor.

Apple uses a secure wireless connection between the keyboard and the Secure Enclave module in an Apple silicon Mac to manage Touch ID. That technology is the Secure Enclave.

Apple requires the use of Touch ID or Face ID with its iPhone anti-theft feature, Stolen Device Protection.

Apple lets you choose to enable Touch ID or Face ID to unlock your device, use Apple Pay, pay for items in Apple’s various stores, validate that you want to automatically fill in a password field in Safari and some other locations, and switch between user accounts when fast user switching is turned on. Some third-party apps offer Touch ID or Face ID as a verification option.

Why Apple Pay turns itself off

You may find that your Mac has disabled Apple Pay without a notification, and you notice only when you attempt to use it in Safari or open System Settings > Wallet & Apple Pay.

This can happen for several reasons:

  • Security level changes: If you lower the level of security for an Apple silicon Mac, you may see the message “Apple Pay has been disabled because the security settings of this Mac were modified.” See how macOS protects its own system files.
  • Laptop lid closed: If you have a laptop, its lid must be open. The exception? If you have an Apple silicon laptop Mac paired with a Magic Keyboard with Touch ID, you can use the keyboard’s sensor.
  • System out of date: Apple says that the “Install system data files and security updates” box should be checked for automatic installation of those files in Software Update. See how to set up automatic security updates.
  • Insecure miscellany: Apple also says ambiguously it disables Apple Pay “when it detects third-party software or malware that affects its ability to keep your payment information secure.”

Enroll in Touch ID

You can enroll your device to use Touch ID via Settings/System Settings > Touch ID & Password. Click or tap Add Fingerprint, then follow the prompts to fill in the fingerprint’s main portion, and then the edges. On a Mac, click Done to finish.

I always name the fingerprint descriptively by clicking or tapping it and then typing text.

Naming fingerprints can be a security or personal safety weakness, allowing someone who wants to coerce you to know which finger to force. However, they would also need to open the Touch ID settings to find out.

You can lock your device against Touch ID by using the wrong fingertip five times in succession; see the lockout section below. This is a good trick when you want to prevent being physically coerced into unlocking your Mac.

I like to enroll at least two of my fingers, because it’s a one-time process per fingertip and it lets me avoid remembering which finger is the right one. You can have a total of three on a Mac or five with an iPhone or iPad. Add other people in your household if you want them to be able to unlock your device or use other Touch ID-required features.

Enroll in Face ID

Face ID for the iPhone and iPad Pro (models noted above) uses an infrared laser and sensor to project and measure 30,000 separate data points on a person’s face to create a profile while also capturing other flat views. Subsequent logins repeat those tasks and introduce randomization, allowing the phone to compare the current face with the stored profile and detect face forgery.

iPhone and iPads with Face ID can recognize just one face plus an “alternate appearance,” or a common secondary appearance of yourself, like with any or different makeup, hat, or glasses. Face ID has worked in portrait orientation since its introduction on all supported devices. Landscape authentication works on all supported iPads and iPhone 13 series models and later.

Enrollment uses a similar process to Touch ID: you use Settings > Face ID & Passcode, and choose Enroll Face. The process has you move your head in a circular motion framed on screen until enough information has been gathered.

Apple says they track and retain temporary updates when they find a good match that falls outside their ideal parameters. These temporary updates are good for only a “finite” number of unlocks, which is a little vague. Maybe it’s to cope with temporary clothing choices or eyebrow plucking? A change in glasses?

You can tap Set Up an Alternative Appearance, useful if you have different ways you make yourself up or attire yourself. Apple has never made fully clear how different that can be.

Face ID relies on an “attentive” expression when you log in. This prevents unlocking the phone or tablet when you’re just glancing past the Lock screen, and it requires someone to have their eyes open. Apple says you can unlock wearing sunglasses. The emitters and sensors are designed for use in all lighting conditions, both indoors and outdoors. The alternate appearance helps here, too.

Apple offers support for facial recognition while wearing a mask with iPhone 12 models and later in portrait orientation only. Here’s how to set up the Face ID with a Mask feature:

  1. Go to Settings > Face ID & Passcode.
  2. Enter your passcode.
  3. Tap Face ID with a Mask while wearing a mask typical of the kind you normally wear.
  4. Apple now informs you of the risks and nature of Face ID with a Mask. Tap Use Face ID with a Mask to continue.
  5. While wearing a typical mask, tap Get Started and walk through the facial training system you’re already familiar with for unmasked Face ID.

Apple appears to ignore most of the mask area, so if you use patterned cloth or medical-grade masks, it shouldn’t prevent you from swapping out masks.

If you wear glasses normally with a mask, wear those while setting up Face ID with a Mask; my current enrollment shows “1 pair of glasses added.” You can have a total of four sets of glasses. Add more by tapping Add Glasses.

Face ID can be delightful as you can merely raise an iPhone or iPad to wake it and, while glancing attentively, the device unlocks.

With Apple Pay at a store payment terminal or in conjunction with Apple Pay in Safari for Mac, you have an extra step even with an unlocked iPhone or iPad. A message appears requesting payment. You double-tap the side or top button, then glance to approve the payment.

For the best results when using Apple Pay with Face ID while wearing a mask, first double-press the side button and authenticate with Face ID; then, with the screen showing “Hold Near Reader,” hold your device to the terminal. I adopted this after finding the angle of terminal, mask, and Face ID sensor were often out of alignment.

Although I recommend setting a strong passcode, you may wind up entering your passcode more frequently with Face ID than with Touch ID for a few reasons:

  • Face ID is good but not perfect; bright light can prevent a match.
  • Some models and brands of sunglasses use optical filters that apparently prevent a good or reliable match.
  • When the sensors can’t perform as exact a match as required, they defer to the passcode. This happens routinely but not constantly.
  • Face ID requires a first-use step with Ask to Buy, used for parents or guardians to approve children’s purchase requests. While Touch ID may be used without any preamble, on Face ID-equipped devices, the first time there’s an Ask to Buy request, you have to enter your Apple Account password. You can then enable Face ID for future approvals.

When biometric lockout happens

Apple disables Touch ID and Face ID in a number of cases. Technically, the operating system flushes a kind of temporary permission for accessing certain data. Entering the passcode refreshes that access. Here are several cases in which you’re required to enter the passcode again:

  • After five incorrect fingerprint or facial recognition attempts. Apple notes, in a parenthetical in their security documentation: “(though for usability, the device might offer entering a passcode or password instead of using biometrics after a smaller number of failures)”.
  • After a restart.
  • When you’ve marked the device as lost via Find My.
  • When you add or remove fingerprints or refresh Face ID.
  • When you try to visit Settings/System Settings > Touch ID/Face ID & Passcode.
  • After you try to use Emergency SOS on an iPhone to make an emergency call. This can be changed in Settings > Emergency SOS.
  • After an attempt to view your Medical ID is made on your iPhone.
  • After 48 hours of a device not being unlocked with Touch ID, Face ID, or an account password.

There’s one more case that’s hard to put into a bullet point. There’s a special countdown clock with two phases. It resets each time you enter your passcode. A 156-hour countdown begins (six and a half days). After that period, a second timer starts a four-hour countdown. If, during those last four hours, you don’t use Face ID or Touch ID to unlock your iPhone or iPad, the next time you use it, you’ll be required to enter your passcode.

You’re probably thinking: “Why?! Why, Apple?! Why!!!” Apple has never made a public statement after this biometrics lockout was added several years ago. The best I can figure, they want to ensure you have to enter your password on a regular basis so it doesn’t fall out of your brain. Now, should you be expected to keep track of the above clocks? No! Not at all! However, if you’re asked for your passcode every week or so when you wake up, and wonder why, that’s probably the reason.

You can make a variety of medical information available at Settings > Health > Medical ID. Once you create this, anyone can attempt to view it via the emergency dialer screen. Understandably, this signals your iPhone or iPad is in someone else’s hands, so locking out biometrics is a logical move.

Also, if you have Face ID with a Mask enabled, Apple reduces the interval between passcode requests on your iPhone to 6.5 hours. Every time you use Face ID (with or without a mask), enter the passcode, or use your Watch to unlock your iPhone, the 6.5-hour timer resets its countdown.

Disable Touch ID or Face ID

You may choose to stop using Touch ID or Face ID or want to use it in a more limited fashion.

If you’re in a situation in which you temporarily want to disable Touch ID or Face ID, the easiest way is to hold down either volume button and the side/top button until a screen appears a few seconds later.

iPhones show you the Emergency SOS screen, including Medical ID, if set; iPads show the Slide to Power Off button. At this point, Touch ID or Face ID is disabled, no matter what action you take. Typically, tap Cancel. (For more strategies, see how to set a stronger iPhone passcode.)

You can access your iPhone or iPad after this only by entering your passcode. However, that re-enables Touch ID or Face ID. In some countries and conditions, you can refuse to enter your passcode.

If you don’t want either biometric capability available—for instance, while crossing a national border—go to Settings > Touch ID/Face ID & Passcode and disable the four “Use Touch ID/Face ID For” switches.

We are all fallible, and the way of all flesh is to age—and sometimes we forget things. I can’t tell you how many times I have “forgotten” a password because I try to remember it, but fortunately I then try to use my fingers to type it, and they “remember” it for me.

If you can’t log in to your main account on your Mac because the password isn’t accepted, you have several options.

Resetting your password on a Mac locks your login keychain, because it’s permanently locked to the account password; see how the Mac keychain works. As a result, you will lose access to locally stored entries, and may have to reset or create a new login keychain manually.

If you forgot the password, try another account

Is there another account you’ve created and can log in to, or another user on the Mac with administrator access? Log in to that administrator account, then go to System Settings > Users & Groups and unlock the pane.

Select your locked-out account and click Reset Password. Now enter and verify the password, adding a hint if you want, and click Change Password. Log out, or use Fast User Switching, then log in to your account with that password.

Reset with the FileVault Recovery Key

FileVault recovery begins when you power on or restart your computer (see how to turn on FileVault). The process takes place using Recovery Assistant. Here’s what to do:

“Apple Account or recovery key” means something different starting in Tahoe than it used to. With Tahoe and Golden Gate, you can either enter the recovery key directly after restarting, or use another of your devices that is also logged in to the same Apple Account to retrieve the recovery key from Passwords. You can no longer use an Apple Account to trigger a macOS password reset if FileVault is enabled.

  1. Go to the login window. To get there, restart your Mac or choose Apple menu > Log Out Account Name.
  2. In the login window, select an account if one isn’t already selected. Then click the question-mark button to the right of the password field.
  3. Click the right-pointing arrow button to restart.
  4. After your Mac restarts, you see the Reset Password utility as the primary screen. This is a special restart mode that doesn’t let you exit into macOS Recovery. Enter your Recovery Key — you can type it in lowercase without dashes, and the utility adds them — then click Next.
  5. If accepted, you’re asked to enter a new password with a hint, and then verify it. Click Reset Password and Verify Password.
  6. Your Mac restarts. Log in with your account and the new password.

If you have upgraded to Tahoe through version 26.3 and have your FileVault Recovery Key stored in your iCloud account, I recommend resetting the key to provide better access to it across your devices, among other advantages. See where to find your FileVault Recovery Key. If you’ve updated to 26.4 or Golden Gate, Apple already made you do this!

Reset via Activation Lock

On Macs with a Secure Enclave coprocessor without FileVault enabled, you can use your Apple Account to reset your password through Activation Lock. Here’s how:

  1. Follow steps 1 to 3 above.
  2. Your Mac restarts and displays an Activation Lock login, showing part of your associated Apple Account. Enter your account name, click Next, then enter the password and click Next.
  3. If successful, a screen appears that notes “Authentication succeeded.” If not, work through the first three steps again.
  4. Click Exit to Recovery Utilities.
  5. Choose Utilities > Terminal.
  6. Type resetpassword and press Return. This opens the Reset Password utility.
  7. Select “I forgot my password” and click Next.
  8. Create a new password as above: enter, verify, and add a hint. Click Reset Password. Your Mac restarts.
  9. Log in with your account and the new password.

This process is also how you reactivate a Mac if it’s been set as lost in Find My.

Reset from recovery mode

There’s a command-line password reset utility available in recovery mode, also, which you can use without having to know the administrator password. Here’s how to reset your password on an Apple silicon Mac:

  1. Choose Apple menu > Shut Down. When your Mac has powered down, hold the power button until you see a prompt that says “Loading startup options.”
  2. Click Options.
  3. Click “Forgot all passwords?”
  4. Choose Utilities > Terminal.
  5. Type resetpassword and press Return. This opens the Reset Password utility, but without the prompt for a Recovery Key.
  6. Select “I forgot my password” and click Next.
  7. Create a new password as above: enter, verify, and add a hint. Click Reset Password. Your Mac restarts.
  8. Log in with your account and the new password.

Apple builds in a huge array of tools that help if your device is physically compromised, as when someone gains access to your iPhone or computer without your permission, someone takes your device away without your knowledge or steals it in order to try to break into it, or when someone extracts hardware (like a drive) from your Mac.

Apple created the chip-based Secure Enclave technology for iPhones and iPads, then expanded it for Macs starting with Intel models. It’s an integral part of Apple silicon Macs. Secure Enclave was a big improvement for device security and data integrity.

Apple created the Secure Enclave coprocessor, first for the iPhone, as a way to provide a tamper-resistant one-way vault to handle encryption secrets, biometric information, and many kinds of private data. The design of the Secure Enclave prevents Apple from accessing information inside it, so the chip that contains it can’t be removed or manipulated without almost always destroying its contents.

Technically, the Secure Enclave is a component of a system-on-chip (SoC), a single piece of silicon that integrates all the functions that previously required separate silicon, such as a CPU, memory, and various I/O chips.

The Secure Enclave coprocessor is part of all Apple silicon Macs. It’s also found in Intel Macs with the T1 chip (for the Touch Bar) or T2 Security Chip; Apple’s support site lists the starting models. All Macs that can run Sonoma or later have a Secure Enclave. You can install macOS 26 Tahoe on all Apple silicon Macs, but only the last series of Intel models support it; macOS 27 Golden Gate works only on Apple silicon Macs. (Most Macs with a Secure Enclave can run macOS 14 Sonoma or later, but fewer work with Tahoe.)

All iPhones from the iPhone 5s onward have it, as do all iPad models introduced since the iPad Air in 2013.

Not surprisingly, Apple’s other devices with its A-series mobile chips also have a Secure Enclave: the Apple TV (HD and later), Apple Watch (all models), and HomePod (all models).

The Secure Enclave is used for a number of different purposes, some of which are directly relevant to this chapter:

  • Touch ID/Face ID: Fingerprints are enrolled and stored securely within, and logins send patterns to the Secure Enclave to match.

Note: The Magic Keyboard with Touch ID enables fingerprint recognition on Apple silicon Macs by pairing directly with the Secure Enclave in a proprietary secure wireless process.

  • SSD encryption: All iPhones and iPads with a Secure Enclave encrypt all data stored on their invisible “startup volume.” All Macs with a T2 chip or Apple silicon processor have an internal SSD startup volume, and that volume has always-on, hardware-based disk encryption.
  • Storage of encryption keys: Apple uses the Secure Enclave to keep the raw stuff of encryption unavailable to anyone—even Apple. Developers can also make use of the Secure Enclave for keys they want their apps to store.
  • Boot integrity (Mac): The Secure Enclave has some hardcoded information that prevents subverting a Mac when it starts up. Startup is a bootstrap process, like “pulling oneself up by one’s bootstraps.” Little bits of software get more complicated pieces of software running in a cascade until the OS is running. With the Secure Enclave, the first stage is loaded from read-only memory—instructions burned permanently into silicon—and each subsequent stage relies on encrypted validation to avoid hijacking.

Secure Enclave has no management associated with it that you have access to. It’s just neatly there carrying out cryptographic and validation operations behind the scenes.

Memory Integrity Enforcement

Starting with A19- and M5-family devices—the iPhone 17, iPhone Air, and M5-based Macs—Apple built in an extra tier of exploit protection called Memory Integrity Enforcement (MIE). Because of Apple’s system architecture and security focus, they have avoided large-scale malware attacks on their platforms that have plagued other companies. Generally, most of us are safe nearly all of the time from all but phishing attacks.

But it doesn’t mean your devices are immune! Smart companies look at the edges to see what’s missing to fill in the picture, and that’s what MIE does, although this may never have an impact on you. MIE is designed to block particular kinds of “mercenary spyware,” as Apple terms it: products designed to execute against specific targets, developed by companies and sold to governments, or created inside government agencies.

For a computing device to run software, the software must be loaded into memory. From memory, the operating system executes code, which carries out operations, including reading from and writing to memory, a video display, external storage, a network, and more. Memory is divided by the system into what used to be logical chunks—that is, the operating system defined these, but there wasn’t a particular prohibition against software writing in any place in memory. Some parts of memory help the operating system; some are drivers or code that manage interactions with hardware; and some are designed for user space, meant for user-loaded programs and data.

Over decades, that’s changed, where the operating system and hardware restrict how different components of a system and loaded software can write to memory. These restrictions have increasingly reduced the attack surface of malware by making it harder for an attacker to circumvent the operating system and run code where they want.

MIE blocks a common form of exploit, in which an attacker pushes more information into a response or request than the code executing it can handle. This can result in a buffer overflow, in which data spills past the end of the chunk of memory set aside for it and corrupts whatever sits alongside (typically values and pointers that other parts of the program rely on). Attackers use that corruption as a foothold to read secrets or take control of the program.

With MIE, these buffer overflows are blocked at the hardware level: every allocation of memory is marked with a secret tag. Malware can’t write into adjacent allocations because those carry a different tag, and the processor refuses at a hardware level to let data be written there, which stops the app from running. MIE also blocks attempts to read or write the same memory locations after an app releases them for other uses, because those locations receive a fresh tag or tags when they’re reallocated; this foils “use-after-free” exploits.

Apple spent years testing this solution and evaluated it against six real-world exploit chains, or sequences of exploited vulnerabilities strung together to gain control or access information that had previously been used against their platforms. Components of MIE blocked all of them. Apple says they couldn’t rebuild any of the chains to get around MIE, even by swapping in new exploits.

Security researchers reported in May 2026 that they had been able to work around MIE in macOS 26.4.1, and disclosed their findings to Apple.

Now, you will likely never be attacked by top-tier criminals or a government’s security agency. (See whether you need more security than Apple’s defaults; and if you are a target, see Lockdown Mode.) These exploit chains previously cost millions to develop and, if created by companies, were sold for huge sums to governments, which deployed them against high-value targets.

Nonetheless, by making such chains far more expensive to build and maintain, MIE reduces the odds that these techniques would ever trickle down to become attacks aimed at the rest of us.

Password lockout protections

On an iPhone, iPad, or Mac with a Secure Enclave, you can’t keep entering an incorrect password without the system taking notice and action. Or, more particularly, someone trying to break into your device cannot try over and over.

After your device has started up and reached a point at which you can enter an account password or passcode, and that secret is repeatedly entered incorrectly, Apple enforces certain limits and timeouts.

An iPhone, iPad, Mac, and even Apple Watch have the same initial timeout and lockout sequence. You can enter your password incorrectly at the login window or passcode entry field up to four times in a row without a delay between entries. However, after the fourth try, Apple adds a one-minute delay before you can try again. After the fifth, five minutes; after the sixth, 15 minutes; seventh, 1 hour; eighth, 3 hours; and ninth, 8 hours. If your tenth password entry fails, the path splits, as described below. Restarting a device doesn’t reduce the time you wait.

If you enabled the erase option on an iPhone or iPad, after the tenth attempt, the device is wiped. However, Apple notes that “consecutive attempts of the same incorrect password don’t count toward the limit.”

With an iPhone, iPad, or Apple Watch, you have to connect to another device: an iPhone or iPad to a Mac or Windows system; an Apple Watch to an iPhone. The device can’t be unlocked, but can be erased and restored.

With macOS, however, Apple provides up to 40 (yes, 40!) additional login attempts through other means to ensure you have the greatest possible options before permanent lockout:

  • Restart in recovery mode (see how macOS protects its own system files). You can try up to 10 times to enter a correct password for a login account after clicking the Options button.
  • If that fails, you have 10 attempts each for:

    • iCloud recovery
    • FileVault recovery
    • Use of an institutional key, if your Mac is managed by a company

If all of the above fails, Secure Enclave locks the volume: it will no longer process any effort to decrypt your startup volume or verify a password you enter. The drive’s data is unrecoverable. The Mac has to be erased and a new system installed to use it again.

The topic of passwords is huge. The key security aspect is narrower: how you secure them.

Apple devices can store and sync passwords in many ways, each with a different risk profile. What follows is how Apple and third-party apps store passwords, and the gold standard for syncing them among devices without increasing the likelihood they could be accessed—even by the company storing them for you.

Apple added passkeys in 2022, a more secure method of logging into a website without leaking secrets and while offering phishing resistance. You use them in lieu of a password plus a second factor, as they combine the same functions. Apple has integrated passkeys into their overall password-management and fill-in approach.

Starting in Sonoma and iOS 17/iPadOS 17, you can also create sharing groups with other people that include both passwords and passkeys. This solves an issue where you may share account access with family members or colleagues but still want the security of a passkey. (This is managed through the Passwords app.)

Apple lets you log in with a passkey to your account on their Apple Account website. This was added to let you log in securely when you weren’t able to use either Touch ID/Face ID or two-factor authentication. For instance, if you’re using a browser on someone else’s Mac and don’t want to enter the password, or you’re connecting via a Google browser on an Android phone.

Apple’s Passwords app can generate a verification code required for login with many two-factor authentication systems and store it as part of a website password entry. Not Apple’s, of course, just all the others.

Hardware security keys

In early 2023, Apple also added direct support for Apple Account logins on devices and their Apple Account website using a standard closely related to passkeys that stores unique login information on a removable hardware security key. These hardware security keys incorporate industry standards, making them compatible across mobile devices and desktop computers, as well as working with websites and native support built into operating systems.

Hardware security keys have to be activated, whether you’re using them with your Apple Account or on a website (Apple’s or anyone’s). On your Mac, iPhone, or iPad, you insert a key into a port (USB Type A, USB-C, or Lightning) or, with an iPhone or iPad, bring a key with NFC near your device. You then press a trigger on the key to start the interaction.

Hardware security keys are obviously physical items you need to exercise distinct precautions around. Their contents are one-way vaults, much like the Secure Enclave in Apple hardware, and can’t be backed up. Make sure you have safeguards in place to avoid losing or damaging them, and to ensure they’re not stolen. Treat them like a stack of $100 bills.

Apple requires two hardware security keys to enroll in that method for your Apple Account, for just that reason. If one is broken or lost, hey, you have a second. You can enroll more than two.

Where your secrets reside

Starting with iOS 18, iPadOS 18, and macOS 15 Sequoia, Apple made the Passwords app the primary built-in interface for accessing secrets, whether website logins or app passwords. Previously, Apple had a Settings section for Passwords in iOS and iPadOS, and a Passwords tab in Safari for macOS.

Even earlier, Apple steered you to Keychain Access, a utility that still exists, and which provides lower-level access to all manner of passwords, codes, secrets, and certificates managed on your Mac. See how the Mac keychain works. There’s no iOS/iPadOS equivalent.

On an iPhone, iPad, or Mac, you can enable Passwords via iCloud settings, which syncs all your app-based passwords and website logins across all the devices you own that are also logged in to the same iCloud account and have Passwords sync enabled.

Go to System Settings/Settings > Account Name > iCloud and choose Passwords or Passwords and Keychain. Enable “Sync this Device type.”

iOS and iPad app passwords use a mapping that associates them with a website, which can cause problems when you signed up in an app or at a website and then try to log in at the other entry point. The website address might not match the one provided by the app, or the app might not incorporate the right website domain. For instance, the website might use login.example.com while the app points to api.example.com.

You have two options to work around this when it happens. First, you can tap or click Passwords, then search for the domain, app, or site, and select the password entry. You’ll be warned about filling in the password. The better path is to open Passwords, find the entry, select it, tap or click Edit, tap or click Websites, then enter variants on the domain.

Browsers other than Safari have their own password storage systems for local storage and syncing. For example, Google Chrome can sync across all your apps linked to the same Google account and makes passwords available through a web-based password manager, which I have more to say about below. (Apple lets you use iCloud Passwords synced items with Chrome by installing an extension, described later.)

Third-party password managers are a boon for people who work across ecosystems or have more nuanced needs to share passwords and other kinds of data securely. Some offer Android, Windows, and Apple apps, plus browser-based access, and let you set up multiple shared secure vaults or storage areas with different sets of people. These third-party systems also have native plugins for Safari and other browsers.

How your secrets are secured

It’s important to know how password vaults manage the encryption and security of your data, but it can also be a bottomless well of detail. In the following entries, I explain, from a top-level view, how Apple manages these aspects for the Apple Keychain and for Passwords synced via iCloud, how other well-designed password managers do the same, and Google’s shortcomings in that regard.

Local passwords and passkeys

On an iPhone, iPad, or Mac, passwords and passkeys are stored in a system keychain. This is invisible to iPhone and iPad users, but you can view that secure information on a Mac via the Keychain Access app. When you enter your account password or device passcode, the keychain is unlocked for use across the device, though Apple requires biometric or password/passcode authentication to apply passwords for most logins even after that.

When you launch Keychain Access, Apple shows a dialog that says, “Manage Your Passwords in the new Passwords App.” You can then click Open Passwords (highlighted in blue) or Open Keychain Access. If you never want to be prompted again, check “Do not show this message again.”

Passkeys are stored in the keychain, but you can’t view their contents—only that you created them—because they’re based on long sequences of digits that form encryption keys meant to be kept strictly private; even displaying them reduces your security. A Mac makes a passkey available when required to log in to a website. Other browsers and apps that incorporate webpage views can also tap into Apple’s system framework to securely use passkeys.

In the Passwords app, you can view passkeys in their own category, although the entry also includes the login information used when you enrolled, such as username and password.

If you have a website login with a password, initially set up with two-factor code-based verification and then transitioned to a passkey, all those elements appear in a single Passwords manager entry.

You’ll also notice that, if you use Google Chrome in Sonoma or later, the browser opens its own compatible passkey validation system for Google account logins.

Keychain data on its own never leaves your machine, and when backed up, the associated files are encrypted. Locally stored keychain entries are backed up by full-disk encryption on all Apple silicon Macs. Your device passwords and passcodes are the only real weak points.

Apple and the rest of the industry agreed on a standard for passkeys, and also agreed to make passkeys securely exchangeable among ecosystems. Well, the first part was true first; the second took years to emerge, finally becoming a reality in 2025 with the version 26 operating systems. With 1Password, Bitwarden, or Dashlane installed, you can move passkeys (and other passwords) between them and Passwords; with two or more installed, they can transfer between each other.

iCloud Keychain for synced data

iCloud relies on endpoint security with locally stored encryption keys that never leave your Mac, iPhone, or iPad. Data is encrypted in transit, and the strongly encrypted data when synced or stored in iCloud is useless without these device-based keys, which are stored in the Secure Enclave on any hardware that has one.

With two-factor authentication (2FA) enabled on your iCloud account—more or less mandatory these days—it’s effectively impossible for someone in most circumstances to gain access to your synced and stored Passwords entries. They would need all three of the following:

  • Your iCloud password
  • Either, with standard code-based 2FA:

— Access to one of your trusted devices that they had the passcode or password for or could otherwise unlock to receive a 2FA token, or a trusted phone number (or hijack a phone number)

— The device password for one of your other Apple devices that’s already synced. When you add a new device to iCloud syncing of Passwords, Apple has you prove yourself by entering the password for an existing device in your set.

  • Or, with an Apple Account locked to hardware security keys for 2FA, access to one of the two or more hardware security keys associated with your Apple Account.

However, there’s one flaw in the above, which is covered in how thieves steal iPhone passcodes: if someone can obtain your iPhone and its passcode, they may be able to use the phone to trigger a reset of your Apple Account password. See how to turn on Stolen Device Protection for advice on preventing that.

Don’t worry about entering your passcode for Passwords syncing: Apple doesn’t know your passcode or store it or transmit it unencrypted. Instead, when you enable Passwords syncing on any device, part of the process bootstraps distributing a set of cryptographic elements securely to other devices. It does so by encrypting that set with the password of the device you’re using—but only the one-way encrypted form of the password is used.

On another device, if you don’t enter exactly the same password, when it’s also transformed in the same way, it won’t match the stored version, and it won’t be able to decrypt the syncing keys to add the device you’re on—and blocks a cracker who doesn’t know your other devices’ passwords, too.

A well-designed third-party manager

The system I described just above for Passwords is the same one that’s been implemented by 1Password. (I don’t recommend any other third-party password manager.)

It’s a zero-knowledge security model for syncing across the cloud, in which the parties handling data can’t actually see the secrets and have no access to keys. As you add devices to cloud syncing, you have to prove you have other devices and secrets first. This is true for both companies’ access to your data stores via their websites: all encryption happens locally in the browser; none is ever sent to the companies; and each login session requires proof of certain elevated secrets that no one can intercept.

1Password’s system syncs files blindly, with storage vaults encrypted and stored that way on 1Password’s servers. The master password for the vault is never transmitted in any way, nor are unencrypted entries.

1Password’s approach is close to Apple’s. The big difference? Apple copies all passwords to local storage and doesn’t allow web-based access to entries, even though they’re all stored with device-based encryption at iCloud.com. With 1Password, there’s no permanent local storage, but you can use a secure method for browser-based access if a native app isn’t available.

Google password encryption

If you use Google for password management—or as part of your password-management approach—I recommend upgrading to the device-based encryption option they introduced a few years ago.

Tip: You can check whether you already have it set up: you might have enabled it or been walked through it by Google already. Follow the same steps below.

Use Google Chrome (not another Chromium-based browser) for the following steps:

  1. In the top-right corner of the browser window, click the More button and choose Passwords and Autofill > Google Password Manager.
  2. Click the menu button and click Settings.
  3. If you see Set Up next to “On-device encryption,” click the link and follow the steps. If you see an open-in-new-window button, on-device encryption is already enabled.

You can avoid Google’s password system and rely on Apple’s by installing iCloud Passwords for Chrome. It’s a Chrome extension that manages the local security issues for accessing Passwords. Unlike Google’s system, it works with Chromium browsers.