Skip to main content

Why is the FileVault recovery key important?

Overview

When FileValut is turned on, it is important to have the recovery key backed up on Swif. Why? Because when you forget your account password and want to reset it, you will need the recovery key to reset it.

A device owner will see this notification on Swif Deskapp (macOS) to ask for the local user password so Swif can generate the FileValut recovery key when the FileValut is turned on before Swif is enrolled on the machine. Please don't ignore it so Swif can have the recovery key for security reasons as you will see below.

With FileVault on, If you forget your account password and want to reset the password, the first thing you will be asked is the recovery key. So you can understand how important the recovery key is.


FileVault Recovery Key Retrieval Requirements

The requirements for retrieving a FileVault recovery key depend on the initial encryption state of the device:

  • Enabled via Swif Policy: If FileVault was enabled for the first time using a Swif FileVault policy, the Swif Admin account is not required to retrieve the recovery key.

  • Enabled Prior to Policy Deployment: If FileVault was already enabled on the device before the Swif FileVault policy was deployed, both the FileVault Policy and the Swif Admin account are required to successfully retrieve the recovery key.

Important Note for BYOD Enrollments:
Please be aware that the Swif Admin account may be disabled in BYOD (Bring Your Own Device) enrollment scenarios. For detailed information on managing these settings, refer to Managing BYOD Enrollment for macOS in Swif.

Did this answer your question?