If your Mac is ever stolen, a standard user password might not be enough to protect your data. A knowledgeable thief can easily plug a bootable USB drive into your Mac, hold the Option key during startup to bypass the internal hard drive, and use specialized software to completely wipe your Mac and reinstall macOS, allowing them to resell the machine.
To prevent this, Apple includes a highly secure, low-level security feature called a “Firmware Password.” When enabled, the Mac will demand a password at the absolute lowest hardware level if anyone attempts to boot the machine from an external USB drive, a secondary partition, or the Recovery Console. Warning: If you forget your Firmware Password, you cannot reset it yourself. You must physically take your Mac to an Apple Store with original proof of purchase.
How to Enable a Firmware Password on an Intel Mac
Note: This process only applies to older Intel-based Macs. Newer Macs with Apple Silicon (M1/M2/M3 chips) handle this automatically via “Activation Lock” when Find My Mac is enabled.
- Click the Apple Logo and select Restart…
- Immediately as your Mac powers back on, press and hold Command + R until you see the Apple logo or a spinning globe. This boots the Mac into macOS Recovery.
- When the macOS Utilities window appears, completely ignore it.
- Instead, look at the very top menu bar on your screen, click on Utilities, and select Startup Security Utility (or Firmware Password Utility on older versions).
- Click the button labelled Turn On Firmware Password.
- Type a strong, memorable password in the “New password” field, and type it again in the “Verify password” field.
- Click Set Password.
- Click the Apple logo in the top-left corner and select Restart.
Your Mac is now secured at the hardware level. It will boot normally from its internal drive without prompting you, but if anyone ever holds the Option key to try and boot from a USB stick, the screen will instantly lock and display a padlock icon, demanding the Firmware Password before proceeding.