Before you start
- Finish Guardrails on the device.
- Add the relevant DNS, router, browser, and account steps in Friction.
- Pick one trusted person who is willing to say no.
- Make an inventory of every password, passcode, recovery key, parent account, router login, and admin account that can undo the setup.
- Make an inventory of every screen too: old phones and tablets in drawers, the smart TV and games console browsers, an e-reader, a work laptop, and any device you could borrow. Reset and give away what you do not need; see every other device.
- Move those recovery paths to the trusted person.
The lockout checklist
| Control | Weak version | Strong version |
|---|---|---|
| Device passcode or Screen Time code | You set it and remember it. | Trusted person sets it and stores it outside your devices. |
| Administrator/root account | Your daily account is admin. | Daily account is standard. Trusted person holds admin password. |
| DNS/router account | You can log in and change DNS. | Trusted person owns router login or DNS dashboard. |
| Recovery email/phone | You can reset any password alone. | Recovery goes to the trusted person or requires them to participate. |
| Factory reset or external boot | You can reset the device and start over. | Disk encryption keys, firmware passwords, MDM, and account recovery are not under your sole control. |
iPhone / iPad lockout
For the one thing Screen Time cannot do — stopping a filtering DNS profile being switched off — see DNS lock. Also consider allowlist mode, which is the strongest built-in web block and reaches in-app browsers. Since iOS 26.4 a Screen Time-based blocker can also be protected by the passcode; see what actually holds on an unsupervised iPhone.
Use Screen Time plus trusted-person recovery
- Complete iPhone / iPad Guardrails.
- Have the trusted person set the Screen Time passcode.
- Set Web Content to Limit Adult Websites or Only Approved Websites.
- Set Installing Apps, Deleting Apps, and, under Allow Changes To, Passcode & Face ID, Accounts and Cellular Data to Don't Allow.
- Remove unneeded browsers, VPN apps, proxy apps, and alternate app stores.
- Do not store the Apple Account password in iCloud Keychain or Notes if you can use it to undo the setup.
- When iOS prompts for Screen Time Passcode Recovery as the passcode is set, enter the trusted person's Apple Account. Never the account whose password you know, and do not skip the prompt: skipping removes the only supported recovery route, so a forgotten passcode means erasing the device.
- If the passcode is already set, have the trusted person change it and answer that prompt correctly this time. There is no way to audit the stored recovery account after the fact.
- Add router or DNS filtering so Safari is not the only layer.
The Apple Account captured at Passcode Recovery can reset the Screen Time passcode later through Forgot Passcode?, using only that account's email and password. Recovery email and phone numbers are irrelevant here. If the prompt captured your own account, you hold a complete bypass no matter who typed the passcode. The recovery account does not have to match the account signed in on the device, so using the trusted person's costs you nothing. See Apple's documentation.
A factory reset or recovery-mode restore erases Screen Time entirely, and reactivation only asks for the Apple Account password you already know. On an unsupervised iPhone that path stays open to you permanently. Supervision through Automated Device Enrollment, which re-enrolls the device after an erase, is the only way to close it.
Use supervised device management when normal Screen Time is too weak
- Use this only if you are comfortable with Apple Configurator, MDM, or a managed-device workflow.
- Manual supervision with Apple Configurator erases the device; back up first.
- Use a DNS settings payload, web content filter payload, app restrictions, and profile restrictions through MDM where appropriate.
- Have the trusted person own the MDM admin account.
- Test whether the user can remove the profile, install a browser, add a VPN, change DNS, or reset the device.
Do not supervise or enroll a device you do not own or administer.
Android lockout
Android has a real enforcement mode. See locking Private DNS on Android: it is the strongest lock available on any phone, and the most demanding to set up.
Google offers supervision only for accounts under 18, and there is no supported way to put an adult's account under someone else's control. If you are an adult building this for yourself, the Family Link steps below do not apply to you. Your Android lockout has to rest on the layers that survive without supervision: Private DNS, a trusted person holding your Google Account password and backup codes, removal of extra browsers and app stores, and router-level enforcement. Be honest with yourself about that, because a setup built on supervision you can dissolve in two taps is not lockout.
Move Family Link and recovery away from the phone
- Complete Android Guardrails.
- Have the trusted person own the parent side of Family Link, where the daily user's account is eligible for supervision.
- Keep the parent Google password off the managed phone.
- Require approval for app installs and purchases.
- Remove extra browsers, VPNs, proxy apps, private browsers, and alternate app stores.
- Set Private DNS to the family-safe hostname from Android Friction.
- Test on Wi-Fi and mobile data.
- Have the trusted person hold the parent account's password and backup codes. See the caution below before moving recovery email or phone numbers on your own everyday account.
Rooted or highly technical Android devices
- If the phone is rooted, assume local filters and hosts files are reversible.
- Remove root if possible before relying on Family Link or Private DNS.
- Disable OEM unlocking and developer options if they are not needed.
- Use a router or DNS account controlled by the trusted person.
- Use a carrier or account-level solution if mobile data is the bypass.
Chromebook / ChromeOS lockout
Owner-account lockout
- Complete Chromebook Guardrails.
- Use the trusted person's account as the owner account when practical.
- Turn off guest browsing.
- Restrict sign-in to approved accounts only.
- Use Family Link on the daily account, subject to the age limit described under Android lockout.
- Remove or block proxy, VPN, remote desktop, and alternate-browser extensions.
- Do not leave the owner password available to the daily user.
Anyone sitting at the sign-in screen can press Ctrl + Alt + Shift + R to Powerwash the device, and whoever signs in first afterward becomes the new owner. No password is needed, and it takes a couple of minutes. Everything in this list is erased by that. If a Chromebook is your real bypass device, the managed path below is the only version of this that holds.
Managed ChromeOS path
- Use Chrome Enterprise, school management, or another legitimate managed-device setup when personal settings are not enough.
- Restrict guest mode, unmanaged sign-in, extensions, developer mode, and URL access.
- Use URL allowlists for the hardest setup.
- Have the trusted person or organization own the admin console.
- Test after powerwash or account removal attempts if your policy model permits those tests.
Windows lockout
Use standard daily account and separate admin
- Complete Windows Guardrails.
- Create or keep one administrator account for maintenance.
- Create a separate standard account for daily use.
- Move all daily browsing, work, and entertainment into the standard account.
- Have the trusted person change and keep the administrator password.
- Put the daily account in a Microsoft family group as a member, with the trusted person as organizer. Only the organizer can change a member's filters, and a member cannot leave on their own. See Windows Guardrails.
- Remove admin rights from the daily account.
- Keep Microsoft Family Safety active if you use a managed Microsoft account.
- Use Edge if you rely on Microsoft Family Safety web filtering.
Block app and browser bypasses
- Use browser policy from Windows Friction to disable browser DNS-over-HTTPS.
- Use AppLocker or App Control for Business, formerly Windows Defender Application Control. AppLocker now enforces on every edition of Windows 11 including Home, which makes it a hazard there rather than an exemption, since Home has no policy editor to undo a bad rule.
- Start application-control rules in audit mode.
- Block portable browsers, VPN clients, proxy tools, unapproved installers, and user-writable executable paths.
- Keep the rule-changing administrator account with the trusted person.
- Test from the standard account after every rule change.
Reduce offline reset and external-boot bypasses
- Turn on device encryption. It is available on every edition of Windows, and recent versions dropped the old hardware requirements. Protection only arms when an administrator signs in with a Microsoft account: until then the drive is encrypted but the key is left unprotected. Have the trusted person's admin account do that sign-in, which also escrows the recovery key to their Microsoft account, and confirm encryption is actually on.
- Store the BitLocker recovery key with the trusted person, not in a place the daily user controls.
- Check aka.ms/myrecoverykey from the daily user's Microsoft account. Windows escrows the key to the account of whichever administrator armed encryption, so the copy should sit with the trusted person, not the daily user; if one is there, remove it.
- Remove or rotate any escrowed copy the daily user can still reach, or accept that BitLocker is not part of your lockout.
- Use Secure Boot where supported.
- Use a UEFI or firmware administrator password only if you understand how to recover it for your device model.
- Prevent booting from USB or external drives if your firmware supports that policy.
- Close the sign-in-screen reset. Holding Shift while choosing Restart, then Troubleshoot -> Reset this PC -> Remove everything, asks for no password by default and, with the default TPM-only encryption, no recovery key either, so a standard user can wipe to a fresh install where they are the administrator. Set the
RecoveryEnvironmentAuthenticationpolicy to require a sign-in (Pro and Enterprise, via policy or registry), or use TPM plus a startup PIN, alongside the firmware password and USB-boot lock. Then verify by attempting it from the daily account. - Keep purchase receipts and OEM recovery information with the trusted person.
Firmware passwords and encryption recovery keys can create real lockouts. Store them carefully with someone reliable, and keep a second copy somewhere the daily user cannot reach but that does not depend on one person staying reachable. See the redundancy rule.
Handing over the recovery key limits offline and external-boot tampering. It does not stop normal use: the daily user's own Windows sign-in still unlocks the drive.
Mac lockout
Use standard daily account and separate admin
- Complete Mac Guardrails.
- Create a standard account for daily use.
- Keep one separate administrator account for maintenance.
- Have the trusted person change and hold the administrator password.
- Use Screen Time with the trusted person holding the Screen Time passcode.
- Remove extra browsers, VPN apps, proxy tools, and unneeded installers.
- Use DNS or browser policy from Mac Friction.
Use FileVault and startup security carefully
- Turn on FileVault if appropriate for your Mac.
- When macOS asks how you want to be able to unlock the disk, choose the recovery key option rather than iCloud account unlock. Letting your iCloud account unlock the disk leaves recovery in the hands of the person you are trying to restrain.
- Store the FileVault recovery key outside the Mac and away from the daily user.
- Have the trusted person enable FileVault from the administrator account. On macOS 26 the recovery key is saved to the iCloud Keychain of whoever turns it on and is readable in the Passwords app on every device signed into that Apple Account, so enabling it from the daily user's account hands them the key. Afterwards, check the Passwords app on the daily user's devices and confirm no copy is there.
- Use startup security settings on supported Macs to reduce external-boot tampering.
- On managed Macs, use MDM to enforce profiles, content filtering, app restrictions, and browser policy.
- Keep MDM, local admin, and recovery-key control with the trusted person or organization.
Do not lose FileVault recovery. A strong lockout can also lock out legitimate recovery. If you forget both the login password and the recovery key, the data is gone for good, so keep the key in at least two places the daily user cannot reach. See the redundancy rule.
Linux lockout
Remove daily sudo access
- Create a non-sudo daily account.
- Have the trusted person hold root, sudo, or admin credentials.
- Configure DNS, hosts, firewall, and browser policy from Linux Friction from an admin account.
- Use the daily account only for normal work.
- Check that the daily account cannot edit
/etc/hosts, change DNS, install browsers, start VPNs, or change firewall rules.
Protect against live-USB and offline edits
- Use full-disk encryption if appropriate.
- Store the encryption recovery passphrase with the trusted person.
- Use firmware boot restrictions where supported and recoverable.
- Block DNS at the router so the Linux machine is not the only layer.
- Do not keep unencrypted backups of the admin credentials on the same device.
Router and network lockout
Make the home network enforce the same rule
- Set family-safe DNS on the router.
- Block or redirect outbound DNS to other resolvers.
- Block DNS-over-TLS unless it goes to your chosen resolver.
- Handle IPv6 DNS.
- Disable or filter guest networks.
- Have the trusted person hold the router admin password.
- Have the trusted person hold the DNS provider, NextDNS, CleanBrowsing, AdGuard, Pi-hole, or firewall admin password.
- Store router recovery instructions with the trusted person.
Remember what the router cannot control
- Mobile data.
- A neighbor's Wi-Fi or public Wi-Fi.
- A separate hotspot.
- A device using a VPN or browser DoH profile unless you also manage that device.
- A person with physical access who can reset the router and knows how to reconfigure it.
Third-party tools to consider
These are examples of categories to evaluate. They are not replacements for account separation and trusted-person control.
Hard blockers
Cold Turkey, Freedom, Focus, or similar tools can add scheduled app and site blocking. Use a trusted person for override credentials.
Accountability tools
Covenant Eyes, Accountable2You, Qustodio, or similar products can add reporting or device visibility. Check platform support before relying on them.
DNS and network tools
NextDNS, CleanBrowsing, AdGuard DNS, Pi-hole, and AdGuard Home can add category filtering, allowlists, logs, and router-level controls.
Managed-device tools
Apple MDM, Chrome Enterprise, Microsoft Intune, and similar platforms are appropriate when you need enforceable policy and can administer it correctly.
Reality check
A determined technical person with sole ownership of every account, recovery path, router, and device can eventually remove most blocks. Lockout works by removing sole ownership from the moment of temptation: the trusted person holds the reset path, the daily account lacks admin rights, and the network enforces the same rules.
Lockout references
Apple device supervision
Apple's documentation on supervised devices and managed control.
Apple FileVault recovery
Apple guidance for FileVault and recovery-key handling.
BitLocker recovery key
Microsoft's recovery-key reference for encrypted Windows devices.
AppLocker overview
Microsoft application-control guidance for supported Windows editions.
Chromebook sign-in controls
Google guidance for limiting who can sign in and turning off guest browsing.
ChromeOS device settings
Managed ChromeOS device policies for stricter environments.