3. Firmware Password
Intel only. Clearing the padlock prompt that blocks Recovery — fills the Firmware Locked column.
Skip this step unless you hit the padlock in Scenario E.
A firmware password lives in the Mac's firmware, not on the disk — erasing the drive does not remove it. Intel-based Macs only (pre-T2 and T2). Apple moved this functionality into recoveryOS on Apple Silicon, gated by FileVault, so there's nothing to unlock on an M-series Mac.
The firmware password itself is supplied separately and is never stored in this doc.
Getting Past It
Enter the firmware password at the padlock prompt. You can't reach the removal tools otherwise.
Removing It
Two ways, both requiring the password. Pick by whether the Mac has a working admin account.
Works even with no macOS account. Use this when the disk is wiped or unknown, or when the GUI throws "no admin found." It authenticates against the firmware password itself, not a macOS account.
# Recovery → Utilities menu → Terminal (already root, no sudo needed)
firmwarepasswd -check # confirm a password is set
firmwarepasswd -delete # prompts for the current password, then clears itRestart, then re-run firmwarepasswd -check to confirm it reports no firmware password set. Record Firmware Locked = Cleared.
The same firmwarepasswd -delete flow works on both pre-T2 and T2 Macs when you know the password. A forgotten firmware password is a different problem — it needs Apple's reset key or an Apple Configurator erase — and is out of scope here since the password is provided.