T2 in new Mac hardware and its impact on virtualizing and running macOS – Role of SMC

In the last few weeks, we have received a lot of inbound questions on the existence of T2 chip in new Apple Mac hardware models and how it impacts the ability to run macOS VMs. In this blog series, we will try to share our knowledge and insights on this topic.



The focus of this first blog is on the role SMC plays in booting macOS and how T2 chip impacts this function. Apple T2 chip can control many aspects of the macOS platform over a single unified bus. One of them is, performing additional firmware validation in a trusted execution environment before supplying it to the chipset for execution. During macOS booting, macOS is accessing the hardware SMC chip to read key validation of the Mac.



In T2 enabled Mac hardware, T2 chip is acting as gatekeeper to SMC. Hackintosh and KVM  based projects, which use Clover, are using the saved key of the SMC key, and bypassing the SMC validation. And, tools like ESXi access to SMC in this hardware is blocked by T2, unable to boot macOS VMs (https://twitter.com/lamw/status/1120368830427959297).



However, any solution that leverages macOS native hypervisor.framework like Anka, can boot macOS VMs without any issues. In this scenario, SMC calls are placed through the hypervisor.framework APIs and T2 is able to pass those onwards.







T2 chip in new Mac hardware not only acts as a gatekeeper during the boot process, but also prevents unauthorized access to internal SSD and Thunderbolt ports. So, even if any tool somehow manages to boot macOS VMs(using saved SMCkeys), it will not have access to the SSD. The workaround would be to use USB or network attached storage which is slow, not scalable and unreliable. More on this in our next blog.



Let us know if you have additional questions/comments in our slack channel.



References – https://www.apple.com/mac/docs/Apple_T2_Security_Chip_Overview.pdf

Share this post

Anka wordmark above a coding agent sending a commit to a CI agent in a fresh Anka VM inside a network boundary, with the Git mirror allowed and the host Mac and neighbor VM blocked
Why CI Agents for macOS and iOS Need Network-Secure Disposable Environments
AI coding agents hand commits to CI agents that make decisions while the job runs. On macOS and iOS, each CI agent needs a fresh VM per commit and a network boundary that limits what it can reach.
Read More
Anka wordmark above two macOS VMs and the host Mac, with VM-to-host and VM-to-VM links blocked by block local and --no-local
Network Isolation for macOS VMs: VM-to-VM, VM-to-Host, and ARP Spoofing Prevention
Meet macOS VM compliance requirements with Anka: block local for VM-to-VM and VM-to-host isolation, --no-local for a hard cut from the host, ARP spoofing prevention, and ipf-style IP filters on shared networking.
Read More
Diagram of Anka Build Cloud monitoring: anka_agent and Controller feed the Anka Prometheus Exporter, Prometheus scrapes it, promtail pushes Node and container logs to Loki, and Grafana reads both for dashboards and alerts
Monitor Anka Build Cloud Disk Space with Prometheus, Grafana, and Loki
Anka Build Cloud exposes node disk, capacity, and instance metrics through the Anka Prometheus Exporter, and its agent and container logs reach Loki through promtail. Here is how to scrape the metrics into Prometheus, graph free disk in Grafana, and alert...
Read More
Cursor Origin logo above an Origin PR to Buildkite to Anka VM flow for macOS CI on hardware you control.
Cursor Origin, Buildkite, and Anka: macOS CI on Agent-Hosted Repos
Cursor Origin now connects Buildkite for CI on Origin-hosted repos. Pair that with Anka's Buildkite plugin so each job runs in a disposable macOS VM on hardware you control.
Read More
Anka wordmark above two isolated VM windows: macOS 14 with Xcode 15, and macOS 15 with Xcode 16, on one Mac.
Running Several macOS and Xcode Versions Side by Side on One Mac
Run concurrent Anka macOS VMs with different OS and Xcode stacks on one host: density math for vCPU and RAM, and why per-project templates beat a shared mutable machine.
Read More
anka-and-kubernetes
On-Demand macOS VMs in Azure DevOps Pipelines with Anka
Run macOS VMs in Azure DevOps Pipelines with Anka. Anklet-style on-demand agents are blocked by Microsoft self-hosted pools today; use a registered agent plus per-job Anka VMs.
Read More
AWS + Anka Build Cost Diagramv3
Ephemeral macOS VMs on AWS EC2 Mac with Anka
Run ephemeral macOS VMs on AWS EC2 Mac with Anka and Anklet. Pack more iOS CI capacity per instance, start jobs in seconds, and cut cost.
Read More
Screenshot 2025-01-08 at 2.16
Enterprise macOS GitHub Actions Runners with Anka
Run self-hosted macOS GitHub Actions at enterprise scale with Anka and Anklet: ephemeral Apple Silicon VMs, more control than hosted runners.
Read More
The Anka product ladder: Develop, Flow, Build, and EC2 Mac as four ascending steps, with Crypt, MCP, Anka Scan, and AMI Scan named below
Which Anka Product Do You Actually Need? A Walkthrough of the Whole Lineup
A situation-first guide to every Veertu product: Anka Develop, Anka Flow, Anka Build, AWS EC2 Mac, Anka Crypt, Anka MCP, Anka Scan, and EC2 Mac AMI Scan, including the moment you move from one to the next.
Read More
anka2024v1-1536x768
A Year of Anka: Highlights from 2024
We’re starting a new annual tradition here at Veertu with our A Year of Anka blog posts. We want our customers to know how the product has grown over the past year and think this is a great avenue to do so. Please enjoy and happy holidays from all...
Read More