Skip to main content
Enable FileVault Disk Encryption (macOS)
Updated over a year ago

Enabling FileVault on a Mac computer encrypts the startup disk using XTS-AES encryption, making it secure from unauthorized access.

Only authorized users can access the startup disk with a password or recovery key, preventing data breaches from lost, stolen, or hacked computers.

FileVault is available on all Mac computers with macOS 10.3 or later and can be enabled through the Security & Privacy preferences pane in System Preferences.

When enabled, FileVault encrypts the startup disk in the background, and a recovery key is prompted to unlock the encryption if necessary.

You can create a policy to enable FileVault for a sub-group of devices in the team. Go to Policy management > Create a new policy.

<a href="https://downloads.intercomcdn.com/i/o/730100256/72694f3fc5a89ff6e153bc23/Swifteam+-+2023-04-28T005450.281.png?expires=1731942000&amp;signature=8a6c44a7e120b53a4de6f088150ee0619abf14eb2520a7854c97f9e0c432720f&amp;req=cyMnF8l%2Bn4RZFb4X1HO4gZP4MtzUz6dJihv2RGa%2Fs1wuyt5cd9UZtdbKFBPd%0A" target="_blank" rel="nofollow noopener noreferrer">https://downloads.intercomcdn.com/i/o/730100256/72694f3fc5a89ff6e153bc23/Swifteam+-+2023-04-28T005450.281.png</a>

Configure the policy name and description and click Continue

<a href="https://downloads.intercomcdn.com/i/o/730116898/946fcc96ebe5fa3f7e67a53c/Swifteam+-+2023-04-28T010109.502.png?expires=1731942000&amp;signature=cd325530a449d07bc29d0212fb0d6cbd3c16b96a0ded523f034da935768528ff&amp;req=cyMnF8h4lYhXFb4X1HO4gbPi2FaIMZ8QJYIKyd6O0ha81SLZI5QOOxgc8fOd%0A" target="_blank" rel="nofollow noopener noreferrer">https://downloads.intercomcdn.com/i/o/730116898/946fcc96ebe5fa3f7e67a53c/Swifteam+-+2023-04-28T010109.502.png</a>

Manage the settings for the selected policy and click Continue

<a href="https://downloads.intercomcdn.com/i/o/730117695/69a7bcce582aa26ebf6998dd/Swifteam+-+2023-04-28T010201.135.png?expires=1731942000&amp;signature=29a1ccc0e47f0bf76a280a377e920eeb554bbe1b850afa0f5169826e912830f4&amp;req=cyMnF8h5m4haFb4X1HO4gVgznoAO759STWWscm%2Bpb1ZpuE0OKwxj3IvpllKu%0A" target="_blank" rel="nofollow noopener noreferrer">https://downloads.intercomcdn.com/i/o/730117695/69a7bcce582aa26ebf6998dd/Swifteam+-+2023-04-28T010201.135.png</a>

Choose the devices and device groups on which the policy will be installed, and click Continue

<a href="https://downloads.intercomcdn.com/i/o/730118369/e9933f9cdb508febaccbbd47/Swifteam+-+2023-04-28T010414.017.png?expires=1731942000&amp;signature=767f2cd433e1cf35a95679f7121d0a6ef78bcf037fde0bd082ac643494d9d2f8&amp;req=cyMnF8h2nodWFb4X1HO4gYojwNxkwY7OF0ZDNxvxiJNALB4X2iDsRddAgW6m%0A" target="_blank" rel="nofollow noopener noreferrer">https://downloads.intercomcdn.com/i/o/730118369/e9933f9cdb508febaccbbd47/Swifteam+-+2023-04-28T010414.017.png</a>

Review the settings and click back to edit. If everything is fine, click Finish to upload the FileVault policy to the selected devices.

---

On the device end, once the FileVault policy is set, Swif will try to retrieve the recovery key in case you need to extract the disk files from the encrypted disk. You can find the recovery key at Device Details > Security > Recovery key.

In some cases, Swif was installed after the encryption was enabled. We won't be able to retrieve the recovery key. We will ask the device owner to give us access to regenerate the recovery key.

If you have any questions about the importance of the FileVault recovery key, you can read it here.

Did this answer your question?