Skip to Content

Third-Party Apps Will Need App-Specific Passwords for iCloud Access From June 15

iCloud AltApp-specific passwords are set to become a mandatory requirement for third-party apps that access iCloud user data, according to an Apple Support email sent out today.

Currently, app-specific passwords are used to allow non-native apps like email clients to sign in to iCloud accounts that are protected by two-factor authentication. The security measure ensures that users can still link up their iCloud account to apps and services not provided by Apple, while also avoiding the need to disclose their Apple ID password to third parties.

However, app-specific passwords will become a basic requirement from June 15, according to Apple. The policy change basically means that users who want to continue using third-party apps with their iCloud account will have to enable two-factor authentication and generate individual passwords for each app.

Beginning on 15 June, app-specific passwords will be required to access your iCloud data using third-party apps such as Microsoft Outlook, Mozilla Thunderbird, or other mail, contacts and calendar services not provided by Apple.

If you are already signed in to a third-party app using your primary Apple ID password, you will be signed out automatically when this change takes effect. You will need to generate an app-specific password and sign in again.

Two-factor authentication ensures that you're the only person who can access your Apple account, even if someone knows your password. To turn it on from any iOS device running iOS 10.3 or later, open the Settings app, tap your name at the top, and then tap Password & Security.

If you're using iOS 10.2 or earlier, you can enable it from Settings -> iCloud -> Apple ID -> Password & Security. If you're on a Mac, go to System Preferences -> iCloud -> Account Details, click Security, and enable two-factor authentication from there.

To generate an app-specific password, sign into your Apple ID account page (https://appleid.apple.com), go to App-Specific Passwords under Security, and click Generate Password.

Popular Stories

AirPods Max 2 Feature

Apple Announces AirPods Max 2 With H2 Chip and More

Monday March 16, 2026 6:12 am PDT by
Apple today unveiled AirPods Max 2, with key upgrades including the H2 chip, increased active noise cancellation, improved sound quality, and features such as Adaptive Audio, Conversation Awareness, Voice Isolation, and Live Translation. The new AirPods Max have the same overall design as the previous generation, with most of the new features coming from the upgrade to the H2 chip:- Adaptive ...
Apple Logo Sketch Feature

Apple Unveiled a Surprise New Product Today

Monday March 16, 2026 10:50 am PDT by
Surprise! Apple today unveiled the AirPods Max 2, despite no rumors suggesting that a new version of Apple's over-ear headphones were imminent. Key upgrades compared to the previous AirPods Max include Apple's H2 chip, increased active noise cancellation, improved sound quality, and features such as Adaptive Audio, Conversation Awareness, Voice Isolation, and Live Translation. AirPods Max ...
apple design award 2025

Apple Announces 2025 Design Award Winners Ahead of WWDC 2025

Tuesday June 3, 2025 10:14 am PDT by
As we wait for WWDC to kick off next Monday, Apple today announced the winners of its annual Apple Design Awards, recognizing apps and games for their innovation, ingenuity, and technical achievement. The 2025 Apple Design Award winners are listed below, with one app and one game selected per category: Delight and Fun - CapWords (App) and Balatro (Game) Innovation - Play (App) and PBJ -...

Top Rated Comments

Chupa Chupa Avatar
115 months ago
That's all fine but it's get confusing and frustrating for the nontechnically oriented user -- and even those of us who are. If Apple really wants to beef up security I don't understand why it doesn't allow keychain access to apps and also require devs to allow TouchID. The best way to ensure security is to encourage people to use long unique random passwords for every app. But you need a password manager to do this and right now Apple's only works in Safari, not apps.

TouchID is available for apps, but not mandated. It should be mandated and keychain access should be made available for devices that do not have TouchID. That would be truly usable feature and set more space between iOS and Android. I mean if Apple is really serious about user security.
Score: 32 Votes (Like | Disagree)
maflynn Avatar
115 months ago
Awful change, makes my computing life more difficult. I think I'll be sure to avoid iCloud as much as possible. I don't want to be forced to use 2 factor. I had turned that on a couple of months ago, and it was just a nightmare trying to use. I don't know why but with multiple iOS and OS X devices, it just didn't work as I had hoped.
Score: 21 Votes (Like | Disagree)
Otelm Avatar
115 months ago
Just to clarify: this only affects apps that access iCloud web services in a non-native way (web API). E.g. those mentioned: outlook, thunderbird, and similar. I'm a developer and I used to have only one such app, which has recently been updated to iCloud drive instead.

This change won't affect apps which use iCloud Drive, keychain (which is already accessible by devs btw, they just don't implement it) and apps which use the CloudKit framework. CloudKit already assigns app-specific containers to apps, while this change only affects services which want to access iCloud outside of their own space (which makes sense, if you consider the security risks).

A kind suggestion: please enable two-factor authentication, the risks in using a single password nowadays are just too great, whatever platform you use.
Score: 18 Votes (Like | Disagree)
itsmilo Avatar
115 months ago
Oh god, no one in my family understands anything above a password as it is. Not even security questions "wtf how does it know where i was born? Thats creepy"
Score: 14 Votes (Like | Disagree)
115 months ago
If Apple really wants to beef up security I don't understand why it doesn't allow keychain access to apps and also require devs to allow TouchID. The best way to ensure security is to encourage people to use long unique random passwords for every app. But you need a password manager to do this and right now Apple's only works in Safari, not apps.
This is already available and has been since iOS 8! The uptake from developers is so low. I have one App (ASOS) that actually uses the API to access the Safari keychain's credentials.

I have contacted lots of the developers of the apps I use to add this as a feature request but it just doesn't seem to have priority, despite it seeming easy to implement.

References:

https://9to5mac.com/2014/06/13/ios-8-lets-apps-access-safari-autofill-credentials-for-quick-easy-login/

https://developer.apple.com/reference/security/shared_web_credentials
Score: 12 Votes (Like | Disagree)
115 months ago
I accidentally changed to two factor auth a while back and had to use these app specific passwords, hated it, it seemed to work for about a week and then stop stating the password was incorrect and had to set up another one each time. After three times I turned two factor auth off and went back to normal. I can see me finally moving away from apple email entirely as it's just not worth the hassle.
Score: 9 Votes (Like | Disagree)