Devices where the user is signed in with their Apple Account must be updated to iOS 16.2, iPadOS 16.2, macOS 13.1, tvOS 16.2, watchOS 9.2, or later, and the latest version of iCloud for Windows. This requirement prevents a previous version of iOS, iPadOS, macOS, tvOS, or watchOS from mishandling the newly-created service keys by re-uploading them to the available-after-authentication HSMs in a misguided attempt to repair the account state.
The user must set up at least one alternative recovery method—one or more recovery contacts or a recovery key—which they can use to recover their iCloud data if they lose access to their account.
If the recovery methods fail, such as if the recovery contact’s information is out of date, or the user forgets them, Apple can’t help recover the user’s end-to-end encrypted iCloud data.
Advanced Data Protection for iCloud can be turned on only for Apple Accounts. Managed Apple Accounts and child accounts (varies by country or region) aren’t supported.