FileVault Guide: Encrypt Every Mac, Keep Every Key

Guide

FileVault is the full-disk encryption built into macOS, so a Mac left on a train opens for nobody without the password or its recovery key. This guide turns it on through Intune, backs up each recovery key before encryption starts, makes sure your IT person can actually read that key, and walks through the day a Mac asks for it.

A lost Mac should cost you a Mac

A Mac without FileVault guards its data with the sign-in screen and good intentions. FileVault encrypts the whole startup disk, so what's on it stays unreadable without a valid password or the recovery key. It's built into every Mac, it costs nothing, and once it's on, nobody notices it again.

Nobody, that is, until someone forgets their password, or leaves, and the Mac asks for its recovery key. If the only copy was shown once on a screen months ago, the data is gone. The point of this guide is that the key always lands somewhere your business controls.

For the owner, in one line: after this, a stolen Mac is an insurance claim, not a data breach, and every recovery key sits where your IT person can read it.

What you need before you start

  • Macs enrolled in Microsoft Intune with user-approved enrollment. Someone has to approve the management profile on the Mac. Without that approval, FileVault policy fails.
  • macOS 10.13 or later for FileVault through Intune, and macOS 14 or later if you want encryption switched on during first setup (Step 4).
  • Each Mac marked as Corporate in Intune. This one catches people out: Intune deliberately hides the recovery key from admins on Macs marked Personal. Check the ownership column before you need a key, not during.
  • A choice you don't get to make: FileVault uses XTS-AES 128-bit encryption, and it can't be changed to 256-bit through Intune or macOS.

Step 1: Create the FileVault policy in Intune

  1. In the Intune admin center, select Endpoint security > Disk encryption > Create Policy.
  2. Set Platform to macOS and Profile to macOS FileVault.
  3. Configure the settings below, assign the policy to a device group of company-owned Macs, and create it.
Setting Value What it does
Enable On Turns FileVault on
Use Recovery Key Enabled Creates the personal recovery key that Intune backs up
Recovery Key Rotation In Months 1 to 12 Replaces the key on a schedule
Location A short note for users Tells people where to find their key (example below)
Allow deferral until sign out Your call Lets the Mac ask at sign-out instead of interrupting work
Defer Force At User Login Max Bypass Attempts A small number How many times someone may skip the prompt before it stops asking nicely

For Location, write something a person can follow at 8 a.m. with a locked Mac in front of them. Microsoft's own example works: sign in to the Company Portal website from any device, open Devices, pick the Mac, and select Get recovery key. Add your support phone number.

Step 2: Know what happens on the Mac

Intune works in two stages. First it prepares the Mac to send its recovery key back, which Microsoft calls escrow. Only after that does encryption start. The Mac then shows the person at the keyboard their personal recovery key, once.

If the prompt never gets accepted, encryption never starts. In Intune that shows up as error -2016341107 (0x87d1138d): the user hasn't accepted the FileVault prompt. That's a conversation, not a bug.

Step 3: Prove it worked

On the Mac, in Terminal:

fdesetup status

You want FileVault is On. Add -extended while it's still working and it shows progress and an estimate of the time left. Then check that a personal recovery key exists:

sudo fdesetup haspersonalrecoverykey

It answers true or false. A "false" can also mean FileVault isn't fully enabled yet, so run it again once status says On.

The Terminal tells you about one Mac. For all of them, go to Devices > Monitor > Device Encryption status in Intune, which lists encryption state and whether a recovery key is on file. A Mac that is encrypted with no key on file is the one to fix today.

Step 4: Encrypt during first setup (macOS 14 and later)

New Macs enrolled through Apple Business Manager can come out of the box encrypted, before anyone saves a file. This needs a Settings catalog policy instead of the endpoint security one:

  • In the Full Disk Encryption category, set FileVault > Force Enable in Setup Assistant to Enabled and Defer to Enabled. Microsoft is explicit that Defer must be on for this to work on macOS 14.4.
  • In the Apple Business Manager enrollment profile, set Await final configuration to Yes, so the Mac waits for this policy before the desktop appears.

Before macOS 14.4, the account created during setup had to be an administrator for this to work. One more reason to keep Macs current.

Step 5: Get a key back on recovery day

  1. In the Intune admin center, go to Devices > All devices and open the Mac.
  2. Under Monitor, select Recovery keys, then Show Recovery Key.

Every reveal is written to the Microsoft Entra audit log with who looked and when. If the button shows nothing, check the ownership setting from the prerequisites: Personal Macs keep their keys away from admins by design.

People can also fetch their own key, without calling anyone, from the Company Portal website at portal.manage.microsoft.com: Devices, pick the Mac, Get recovery key. The Company Portal phone apps show it too.

Step 6: Replace a key once it's been used

A key that has been read aloud over the phone isn't a secret anymore. To replace it, open the Mac in Intune and select Secure > Rotate FileVault recovery key, then Yes. The old key stops working and the new one is backed up in its place. Manual rotation works on Corporate Macs only.

You don't need a global admin for this. The permission is Remote tasks: Rotate FileVault key, and Intune's built-in Help Desk Operator and Endpoint Security Administrator roles include it.

Taking over Macs someone already encrypted

A Mac that was encrypted by hand before it met Intune has a key Intune has never seen. Two ways to fix that, both with the FileVault policy already assigned:

  • The user still has the old key: in the Company Portal website, they select the Mac, choose Store recovery key, and enter it. Intune checks it, then rotates to a new key it holds.
  • Nobody has the old key: on the Mac, generate a new one, which replaces the old key outright:
sudo fdesetup changerecovery -personal

Sync the Mac from Intune afterwards and check that the key shows up under Recovery keys.

One shortcut to be careful with

fdesetup authrestart restarts a FileVault Mac without asking for the password at boot, which is handy for remote updates. Apple's own manual page warns that FileVault protections are reduced during it, because an unlock key is kept in memory for the restart. Use it for a planned restart you're watching, not as a habit.

Back that up with a compliance policy: setting Require encryption of data storage in an Intune compliance policy means an unencrypted Mac can be blocked from company resources until FileVault is on.

Sources

Checked on 2026-10-03 against Microsoft Learn and the fdesetup manual page on macOS 26.5:

More in Macs

Need expert help?

Our team can help you implement these security practices.

Contact Us