Third-Party Apps Will Need App-Specific Passwords for iCloud Access From June 15

iCloud AltApp-specific passwords are set to become a mandatory requirement for third-party apps that access iCloud user data, according to an Apple Support email sent out today.

Currently, app-specific passwords are used to allow non-native apps like email clients to sign in to iCloud accounts that are protected by two-factor authentication. The security measure ensures that users can still link up their iCloud account to apps and services not provided by Apple, while also avoiding the need to disclose their Apple ID password to third parties.

However, app-specific passwords will become a basic requirement from June 15, according to Apple. The policy change basically means that users who want to continue using third-party apps with their iCloud account will have to enable two-factor authentication and generate individual passwords for each app.

Beginning on 15 June, app-specific passwords will be required to access your iCloud data using third-party apps such as Microsoft Outlook, Mozilla Thunderbird, or other mail, contacts and calendar services not provided by Apple.

If you are already signed in to a third-party app using your primary Apple ID password, you will be signed out automatically when this change takes effect. You will need to generate an app-specific password and sign in again.

Two-factor authentication ensures that you're the only person who can access your Apple account, even if someone knows your password. To turn it on from any iOS device running iOS 10.3 or later, open the Settings app, tap your name at the top, and then tap Password & Security.

If you're using iOS 10.2 or earlier, you can enable it from Settings -> iCloud -> Apple ID -> Password & Security. If you're on a Mac, go to System Preferences -> iCloud -> Account Details, click Security, and enable two-factor authentication from there.

To generate an app-specific password, sign into your Apple ID account page (https://appleid.apple.com), go to App-Specific Passwords under Security, and click Generate Password.

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Production Will Reportedly Begin Ramping Up in October

Tuesday July 23, 2024 2:00 pm PDT by
Following nearly two years of rumors about a fourth-generation iPhone SE, The Information today reported that Apple suppliers are finally planning to begin ramping up mass production of the device in October of this year. If accurate, that timeframe would mean that the next iPhone SE would not be announced alongside the iPhone 16 series in September, as expected. Instead, the report...
iPhone 17 Plus Feature

iPhone 17 Lineup Specs Detail Display Upgrade and New High-End Model

Monday July 22, 2024 4:33 am PDT by
Key details about the overall specifications of the iPhone 17 lineup have been shared by the leaker known as "Ice Universe," clarifying several important aspects of next year's devices. Reports in recent months have converged in agreement that Apple will discontinue the "Plus" iPhone model in 2025 while introducing an all-new iPhone 17 "Slim" model as an even more high-end option sitting...
Generic iPhone 17 Feature With Full Width Dynamic Island

Kuo: Ultra-Thin iPhone 17 to Feature A19 Chip, Single Rear Camera, Semi-Titanium Frame, and More

Wednesday July 24, 2024 9:06 am PDT by
Apple supply chain analyst Ming-Chi Kuo today shared alleged specifications for a new ultra-thin iPhone 17 model rumored to launch next year. Kuo expects the device to be equipped with a 6.6-inch display with a current-size Dynamic Island, a standard A19 chip rather than an A19 Pro chip, a single rear camera, and an Apple-designed 5G chip. He also expects the device to have a...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Less Than Two Months Away: Everything We Know

Thursday July 25, 2024 5:43 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
icloud private relay outage

iCloud Private Relay Experiencing Outage

Thursday July 25, 2024 3:18 pm PDT by
Apple’s iCloud Private Relay service is down for some users, according to Apple’s System Status page. Apple says that the iCloud Private Relay service may be slow or unavailable. The outage started at 2:34 p.m. Eastern Time, but it does not appear to be affecting all iCloud users. Some impacted users are unable to browse the web without turning iCloud Private Relay off, while others are...

Top Rated Comments

Chupa Chupa Avatar
94 months ago
That's all fine but it's get confusing and frustrating for the nontechnically oriented user -- and even those of us who are. If Apple really wants to beef up security I don't understand why it doesn't allow keychain access to apps and also require devs to allow TouchID. The best way to ensure security is to encourage people to use long unique random passwords for every app. But you need a password manager to do this and right now Apple's only works in Safari, not apps.

TouchID is available for apps, but not mandated. It should be mandated and keychain access should be made available for devices that do not have TouchID. That would be truly usable feature and set more space between iOS and Android. I mean if Apple is really serious about user security.
Score: 32 Votes (Like | Disagree)
maflynn Avatar
94 months ago
Awful change, makes my computing life more difficult. I think I'll be sure to avoid iCloud as much as possible. I don't want to be forced to use 2 factor. I had turned that on a couple of months ago, and it was just a nightmare trying to use. I don't know why but with multiple iOS and OS X devices, it just didn't work as I had hoped.
Score: 21 Votes (Like | Disagree)
Otelm Avatar
94 months ago
Just to clarify: this only affects apps that access iCloud web services in a non-native way (web API). E.g. those mentioned: outlook, thunderbird, and similar. I'm a developer and I used to have only one such app, which has recently been updated to iCloud drive instead.

This change won't affect apps which use iCloud Drive, keychain (which is already accessible by devs btw, they just don't implement it) and apps which use the CloudKit framework. CloudKit already assigns app-specific containers to apps, while this change only affects services which want to access iCloud outside of their own space (which makes sense, if you consider the security risks).

A kind suggestion: please enable two-factor authentication, the risks in using a single password nowadays are just too great, whatever platform you use.
Score: 18 Votes (Like | Disagree)
itsmilo Avatar
94 months ago
Oh god, no one in my family understands anything above a password as it is. Not even security questions "wtf how does it know where i was born? Thats creepy"
Score: 14 Votes (Like | Disagree)
MR-LIZARD Avatar
94 months ago
If Apple really wants to beef up security I don't understand why it doesn't allow keychain access to apps and also require devs to allow TouchID. The best way to ensure security is to encourage people to use long unique random passwords for every app. But you need a password manager to do this and right now Apple's only works in Safari, not apps.
This is already available and has been since iOS 8! The uptake from developers is so low. I have one App (ASOS) that actually uses the API to access the Safari keychain's credentials.

I have contacted lots of the developers of the apps I use to add this as a feature request but it just doesn't seem to have priority, despite it seeming easy to implement.

References:

https://9to5mac.com/2014/06/13/ios-8-lets-apps-access-safari-autofill-credentials-for-quick-easy-login/

https://developer.apple.com/reference/security/shared_web_credentials
Score: 12 Votes (Like | Disagree)
Nem Avatar
94 months ago
I accidentally changed to two factor auth a while back and had to use these app specific passwords, hated it, it seemed to work for about a week and then stop stating the password was incorrect and had to set up another one each time. After three times I turned two factor auth off and went back to normal. I can see me finally moving away from apple email entirely as it's just not worth the hassle.
Score: 9 Votes (Like | Disagree)