使用 Intune 在受監督的 iOS 裝置上略過啟用鎖定Bypass Activation Lock on Supervised iOS devices with Intune

適用對象:Azure 入口網站的 IntuneApplies to: Intune in the Azure portal
您需要傳統入口網站的 Intune 相關文件嗎?Looking for documentation about Intune in the classic portal? 請移至這裡Go here.

Microsoft Intune 可以協助您管理 iOS 啟用鎖定,這是 iOS 8.0 和更新版本裝置之「尋找我的 iPhone」應用程式中的一項功能。Microsoft Intune can help you manage iOS Activation Lock, a feature of the Find My iPhone app for iOS 8.0 and later devices. 當使用者在裝置上開啟「尋找我的 iPhone」應用程式時,啟用鎖定會自動啟用。Activation Lock is enabled automatically when a user opens the Find My iPhone app on a device. 啟用之後,就必須輸入使用者的 Apple ID 和密碼,才能夠讓所有人:After it is enabled, the user's Apple ID and password must be entered before anyone can:

  • 關閉「尋找我的 iPhone」Turn off Find My iPhone
  • 清除裝置Erase the device
  • 重新啟動裝置Reactivate the device

啟用鎖定對您的影響How Activation Lock affects you

雖然啟用鎖定可以協助保護 iOS 裝置,並提高裝置遺失或遭竊時的復原機會,但是這項功能可能會為身為 IT 系統管理員的您帶來一些挑戰。While Activation Lock helps secure iOS devices and improves the chances of recovering a lost or stolen device, this capability can present you, as an IT admin, with a number of challenges. 例如:For example:

  • 一位使用者在裝置上設定啟用鎖定。A user sets up Activation Lock on a device. 使用者之後離職並歸還裝置。The user then leaves the company and returns the device. 如果沒有使用者的 Apple ID 和密碼,就無法重新啟動裝置。Without the user's Apple ID and password, there is no way to reactivate the device.
  • 您需要一份啟用鎖定已啟用之所有裝置的報表。You need a report of all devices that have Activation Lock enabled.
  • 在重新整理組織中的裝置期間,您想要將某些裝置重新指派給不同的部門。You want to reassign some devices to a different department during a device refresh in your organization. 您只能重新指派啟用鎖定未啟用的裝置。You can only reassign devices that do not have Activation Lock enabled.

為了協助解決這些問題,Apple 在 iOS 7.1 中引進了啟用鎖定略過。To help solve these problems, Apple introduced Activation Lock bypass in iOS 7.1. 啟用鎖定略過可讓您從沒有使用者的 Apple ID 和密碼的受監督裝置移除啟用鎖定。Activation Lock bypass lets you remove the Activation Lock from supervised devices without the user's Apple ID and password. 受監督的裝置會產生裝置特定啟用鎖定略過碼,並儲存在 Apple 啟用伺服器上。Supervised devices can generate a device-specific Activation Lock bypass code, which is stored on Apple's activation server.

提示

iOS 裝置的受監督模式可讓您使用 Apple Configurator 鎖定裝置,並將功能限制在特定商務用途。Supervised mode for iOS devices lets you use Apple Configurator to lock down a device and limit functionality to specific business purposes. 受監督的模式僅用於屬公司擁有的裝置。Supervised mode is used only for corporate-owned devices.

您可以在 Apple 網站 (英文) 上深入了解「啟用鎖定」。You can read more about Activation Lock on Apple's web site.

Intune 如何協助您管理啟用鎖定How Intune helps you manage Activation Lock

Intune 可以要求執行 iOS 8.0 和更新版本之受監督裝置的啟用鎖定狀態。Intune can request the Activation Lock status of supervised devices that run iOS 8.0 and later. 僅針對受監督的裝置,Intune 可以擷取啟用鎖定略過碼並直接發給裝置。For supervised devices only, Intune can retrieve the Activation Lock bypass code and directly issue it to the device. 如果已抹除裝置,您可以使用空白使用者名稱和代碼作為密碼,進而直接存取裝置。If the device has been wiped, you can directly access the device by using a blank user name and the code as the password.

使用 Intune 管理啟用鎖定對公司的好處包括:The business benefits of using Intune to manage Activation Lock are:

  • 使用者可以獲得「尋找我的 iPhone」應用程式的安全性優點。The user gets the security benefits of the Find My iPhone app.
  • 您可以讓使用者執行工作,並使其知道在需要重新規劃裝置時,您可將裝置淘汰或解除鎖定。You can enable users to do their work and know that when a device needs to be repurposed, you can retire or unlock it.

開始之前Before you start

在您可以略過裝置上的啟用鎖定之前,必須先遵循下列指示啟用它:Before you can bypass Activation Lock on devices, you must enable it by following these instructions:

  1. 使用如何設定裝置限制設定中的資訊,來設定適用於 iOS 的 Intune 裝置限制設定檔。Configure an Intune device restriction profile for iOS using the information in How to configure device restriction settings.
  2. iOS 的裝置限制設定 中,於 [一般] 設定下,啟用 [啟用鎖定] 選項。In the device restriction settings for iOS, under the General settings, enable the option Activation Lock.
  3. 儲存設定檔,然後將它指派給您想要管理啟用鎖定略過的裝置。Save the profile, and then assign it to the devices on which you want to manage Activation Lock bypass.

如何使用啟用鎖定略過How to use Activation Lock bypass

重要

略過裝置上的啟用鎖定之後,如果「尋找我的 iPhone」應用程式處於開啟狀態,則會自動套用新的啟用鎖定。After you bypass the Activation Lock on a device, if the Find My iPhone app is opened, a new Activation Lock is automatically applied. 因此,您應該實際擁有裝置,才能執行這個程序Because of this, you should be in physical possession of the device before you follow this procedure.

Intune 的略過啟用鎖定遠端裝置動作即使沒有使用者的 Apple ID 及密碼,也可以從 iOS 裝置移除啟用鎖定。The Intune Bypass Activation Lock remote device action removes the activation lock from an iOS device without the user’s Apple ID and password. 當您略過啟用鎖定之後,裝置會在 [尋找我的 iPhone] 應用程式會啟動再次開啟啟用鎖定。Once you bypass the activation lock, the device turns on activation lock again when the Find My iPhone app launches. 僅當您能夠實際使用裝置時,才略過啟用鎖定。Only bypass the activation lock if you have physical access to the device.

  1. 登入 Azure 入口網站。Sign into the Azure portal.
  2. 選擇 [更多服務] > [監視 + 管理] > [Intune]。Choose More Services > Monitoring + Management > Intune.
  3. 在 [Intune] 刀鋒視窗中,選擇 [裝置]。On the Intune blade, choose Devices.
  4. 在 [裝置和群組] 刀鋒視窗中選擇 [所有裝置]。On the Devices and groups blade, choose All devices.
  5. 從您管理的裝置清單中,選擇受監督的 iOS 裝置,然後選擇 [略過啟用鎖定] 裝置遠端動作。From the list of devices you manage, choose a supervised iOS device, and then choose the Bypass Activation Lock device remote action.

後續步驟Next steps

您可以在 [管理裝置] 工作負載中,於裝置的詳細資料頁面上,檢查解除鎖定要求的狀態。You can examine the status of the unlock request on the details page for the device in the Manage devices workload.