Skip to content

Biometric protection

A biometric-protected key requires Touch ID, Face ID or the device passcode every time it is used — connecting to a server, or signing an agent-forwarding request.

Protected keys are deliberately device-local:

  • They are excluded from iCloud Keychain sync.
  • To use one on another device, re-import it there or transfer it with Key Handoff.

This is a security feature: your most sensitive keys never leave the hardware you enrolled them on.

Turn on protection for a key in the key library. The requirement applies immediately to every profile that uses the key.