3 ms·
Well the good news is that changing the startup security preference for T2-featured Macs is straight forward and easily user accessible. Via Recovery partition,
by dargos 8y ago
Well the good news is that changing the startup security preference for T2-featured Macs is straight forward and easily user accessible. Via Recovery partition, it has replaced the standalone Firmware Password Utility located in the Utilities folder and is referred to as Startup Security Utility.
Default installations of MacOS do enable both the Secure Boot option "Full Security" and disable the Mac's ability to startup from external media however via this utility you can change that preference to "allow booting" for the latter and an option called "Medium Security" for the former. Medium Security would allow the Mac to startup from any previously trusted & signed OS, thus allowing the user the ability to downgrade (& without an internet connection) if needed. I can personally attest that if these T2 Macs were ever eligible for a build of MacOS, they can downgrade to it.
The real question is which users or administrators are majorly impacted by the T2 Mac's inability to boot into a network volume. From what I've heard, this is a T2 restriction that cannot be bypassed. This will fundamentally change the way ACMTs can service Macs going forward.
-About Startup Security - Apple Support: https://support.apple.com/en-us/HT208198 https://support.apple.com/en-us/HT208198
Off the top of my head, Macs with T2:
2017 iMac Pro/
2018 13" MBP/
2018 15" MBP/
Late 2018 MacBook Air/
Late 2018 Mac Mini