Techrider.live

Dante Device Lock: Protect Routes and Recover a Forgotten PIN

6 min read · Updated October 6, 2026 · FOH and monitor engineers, system technicians, AV network engineers, broadcast operators, production managers, venue technicians, integrators, and touring audio teams

Use Dante Device Lock without interrupting existing audio, plan PIN ownership, and recover a locked device safely when the PIN is unavailable.

TL;DR — Dante Device Lock uses a four-digit PIN to make a supported device's subscriptions and configuration read-only while existing media continues to flow. Confirm support, record the working route, assign PIN ownership, and lock only after changes are complete. To recover a forgotten PIN, isolate the device, power-cycle it, wait at least two minutes, then use Forgot PIN. Retest routing before returning it to production.

Device Lock protects configuration, not the network

Dante Device Lock is a device-level control in Dante Controller. A locked device can still be monitored, and its established media continues to flow, but its subscriptions and configuration cannot be changed until it is unlocked with the PIN.

StateExisting mediaMonitoringConfigurationNew routing
UnlockedContinuesAvailableEditableAvailable
LockedContinuesAvailableRead-onlyRestricted by the locked endpoint
UnsupportedUnchangedAvailableDevice-specificDevice-specific

Device Lock is not encryption, user authentication, or a replacement for switch security and physical access control. Not every Dante product supports it; confirm the Device Lock column, toolbar padlock, or manufacturer's documentation before making it part of the show plan.

Understand what locking changes

When a transmitter is locked, existing subscriptions continue. An unlocked receiver can remove an existing subscription and reinstate one that the locked transmitter already permits, but a new subscription cannot be made to a locked transmitter. Dante Controller may report an access-control tooltip when a route conflicts with the lock.

A locked receiver is also protected from subscription and configuration changes. If a route change is expected during the show, decide whether the affected device should remain unlocked or whether the change should be completed and verified before locking.

The Dante subscription errors guide helps distinguish an access-control message from format, clock, flow, or discovery failures.

Lock a device without creating a show problem

1. Confirm support and current state

Use Network View's Device Info tab or the padlock in Device View. A supported device exposes an active lock control; an unsupported device shows N/A or a disabled control. Record device name, model, firmware, current subscriptions, and lock state.

2. Finish and test the route

Build the complete show route, including record, broadcast, lobby, comms, and backup feeds. Test audio, clock, and planned failover before making the configuration read-only. A lock preserves the current state; it does not prove that state is correct.

3. Assign PIN ownership

Choose a four-digit PIN through the production's credential process. Record who can retrieve it, where the controlled record lives, and who may unlock the device. Do not place the PIN in a public rider, channel name, or visible console note.

4. Lock in Dante Controller

Open Device View and select the padlock, or use the Device Lock control in Device Info. Enter and confirm the PIN, then lock the device. Confirm the padlock indication and verify that the intended audio continues.

5. Test the protected state

Attempt only the approved non-destructive check: confirm the device remains visible, monitoring data is available, and configuration controls are read-only. Avoid exploratory route changes on a live system.

Plan around residual connections

Dante Controller can warn that a transmitter has residual unused connections from an earlier subscription state. Preparing the device for locking may close those connections and briefly interrupt media from that transmitter. Treat the warning as a change window, not a harmless confirmation dialog.

Before proceeding:

  • identify every destination fed by the transmitter;
  • confirm the route matrix matches the approved design;
  • schedule the lock before doors or during a controlled maintenance window;
  • have the unlock PIN and rollback owner present;
  • verify audio, clock, and route status after locking.

Recover a forgotten PIN safely

Audinate's documented recovery requires physical isolation so the reset applies to the intended device.

  1. Disconnect or power down every other Dante device on that isolated network segment, leaving only the locked device and the Dante Controller computer.
  2. Disconnect and reconnect the locked device.
  3. Wait at least two minutes.
  4. Open the unlock panel and select Forgot PIN.
  5. Reset the device lock, then apply a new PIN if the operating plan requires one.
  6. Reconnect the production network and rebuild or verify every required route.

Do not improvise isolation on a running show network. If the topology cannot be isolated without affecting production, schedule recovery for a maintenance window and follow the device manufacturer's instructions.

Choose what to lock

SituationPractical choiceReason
Fixed venue route after commissioningLock critical endpointsPrevent accidental subscription or configuration changes
Touring system before doorsLock after route and failover testPreserve the approved show state
Device requires planned route changesKeep unlocked under change controlLock would block the required workflow
Mixed fleet with unsupported devicesDocument per-device stateLock coverage is not universal
Forgotten PIN on a live networkDefer to a controlled windowIsolation and retest are required

Device Lock complements a saved configuration. Use the Dante Controller presets guide to preserve routing and device settings for recovery; a lock alone is not a backup.

Device-lock checklist

  • Each device's lock support and firmware are confirmed.
  • The complete route has passed audio, clock, and failover tests.
  • PIN ownership and controlled storage are assigned.
  • Residual-connection warnings are handled in a change window.
  • Existing audio is verified after locking.
  • Planned show changes do not depend on a locked control.
  • Forgotten-PIN recovery includes isolation and a two-minute wait.
  • Unlock, restoration, retest, and escalation owners are documented.

FAQ

What does Device Lock do in Dante Controller?

It makes a supported device's subscriptions and configuration read-only behind a four-digit PIN while leaving monitoring available.

Does locking a Dante device stop audio?

Existing media normally continues to flow. A warning about residual unused connections can indicate that preparation for locking may interrupt media, so lock during a controlled window.

Can I make a new subscription to a locked Dante device?

You cannot create a new subscription to a locked transmitter. Existing subscriptions continue, and route behavior also depends on whether the receiving device is locked.

How do I unlock a Dante device?

Open the device's lock control in Device View or Device Info, enter the four-digit PIN, and select Unlock. Then make and test the approved change.

What should I do if I forgot a Dante Device Lock PIN?

Isolate the device with the Dante Controller computer, power-cycle it, wait at least two minutes, and use Forgot PIN. Reconnect and fully verify the production route afterward.

Make protection part of the handoff

A padlock icon is not an operating plan. Keep each device's approved lock state, credential owner, change window, recovery method, and validation record in Techrider.live with the current network notes so collaborators can edit, save, and inspect history without exposing the PIN.

Related guides