The problem it was built to solve

The scenario is specific and was becoming common: a thief observes the passcode being entered, then steals the phone. With both the device and the code, they can change the account password, disable location tracking, and lock the owner out entirely.

Stolen Device Protection requires biometrics for selected actions and delays certain security changes. The default applies away from familiar locations; Always extends these measures everywhere.

It hardens the account, not the library

The protections apply to account and security operations — changing the Apple Account password, turning off Find My, altering security settings. They do not place a separate credential around your photos.

An unlocked phone does not automatically expose a locked app: opening it requires biometrics without a passcode fallback when Stolen Device Protection applies. An app left unlocked and copies elsewhere remain separate risks.

Familiar locations are part of the model

The default policy requires the extra checks away from familiar locations. Choose Always under Require Security Delay to require them at home and work too.

Check the selected policy rather than assuming familiar locations always bypass the checks or that every action has a delay.

What to do alongside it

  • Enable it on supported iOS versions and confirm it is actually on.
  • Review the familiar-location behaviour and the security-delay flow before you need them.
  • Avoid entering the passcode where it can be observed, since that is the attack it responds to.
  • Use the Hidden collection, app-level locks, or a separate vault for photo-specific separation.

Two misreadings

  • Treating account hardening as though it encrypted your media.
  • Assuming a compromised passcode is no longer a serious problem.

A fictional example

Maya starts with a non-sensitive test: “Enable the feature on supported iOS versions.” Next, Maya follows the second check: “Review familiar-location behavior and security delays.” This fictional scenario demonstrates the decision process; it is not a report of product testing.

Common mistakes

  • Treating account-hardening as media encryption
  • Ignoring a compromised device passcode

What this workflow does not change

  • Treating account-hardening as media encryption
  • Ignoring a compromised device passcode

Questions people ask

Will it stop every photo view?

No. It protects specified actions, including opening locked apps, but does not cover every route to a photo.

Sources and further reading