Which user(s) can activate erased Mac with their device password after Mark As Lost?

I have the following 3 users on my M1 Macbook Air 2020:

  • userA: admin created during macOS installation, no AppleID connected
  • userB: non-admin, its own AppleID connected, FindMy disabled
  • userC: non-admin, its own AppleID connected, FindMy enabled

After I invoke Mark As Lost in Find My iPhone app logged in with UserB's AppleID and rebooting into Activate Mac, I can Erase Mac without providing any user credentials. After Mac is erased, I need to activate it:

  • either by providing AppleID and password
  • OR via Use Device Password option

Now the question is:

Which of UserA, UserB, UserC device passwords should be accepted for "Use Device Password"?


My own experiments gave inconsistent results:

  • after Mac was locked when UserC logged in, I managed to activate it with UserC's device password
  • after Mac was locked when UserB logged in, I failed to activate it with any of UserA, UserB, UserC device passwords: error messages varied between:
    • Activation lock server cannot be reached (obviously while on stable internet connection)
    • The password for this Mac can no longer be used to remove Activation Lock. The password was entered incorrectly too many times

Each experiment takes a couple of hours, so I hope there's official docs / third-party research on the topic.


Some further details of my setup:

UserC's AppleID is an adult, non-guardian member of family owned by UserB.

FileVault enabled during initial MacOS setup; encryption key not associated with any AppleID. Password reset using AppleID is disabled for all users.

From Apple Platform Security, it looks like only the userC (non-admin, its own AppleID connected, FindMy enabled) can unlock the Mac, assuming that his device password is a replacement for iCloud credentials:

If the device is Activation Locked, recoveryOS prompts the user for iCloud credentials of the user that enabled Activation Lock at this time.

BUT it is not said explicitly, so I may be wrong--so I welcome input from you guys.

Which user(s) can activate erased Mac with their device password after Mark As Lost?
 
 
Q