How about enforcing this by contract to shift the responsibility towards the employer, which presumably has more teeth to defend itself from abuses?
Say a clause in every IT worker contract stating that when a LEO asks to unlock any device, a predefined user account must be used to log in. In the OP case, I'd hardly believe they'd send SWAT teams to Cupertino to raid Apple offices.