Profile: FileVault
The "FileVault" profile configures full-disk encryption on Mac computers, controlling when encryption is enforced, whether the recovery key is escrowed with SimpleMDM, and how the device user is prompted to complete encryption.
Apple documentation for this feature is available here.
To create a FileVault profile:
- Make sure the target devices are running macOS 10.9+ and are enrolled.
- Go to Configs > Profiles and click "Create Profile".
- From the list, select "FileVault".
- Configure the settings as desired.
- Assign the configuration to your devices/groups.
Note: Only one FileVault profile can be applied per device.
FileVault settings explained
- Bypasses allowed at login: Controls how many times the device user can defer enabling encryption at login before it's forced. Options range from "Do not encrypt at login" to a specific number of bypasses, or "Unlimited". Selecting "Force encryption at login" enforces encryption on the very next login with no bypasses allowed.
- Additionally request encryption during logout: When enabled, the device user is also prompted to enable encryption at logout, in addition to login.
- Allow user to disable FileVault: When disabled, the device user is prevented from turning off FileVault encryption themselves once it's enabled.
- Store the recovery key with SimpleMDM: When enabled, the personal recovery key generated when the device is encrypted is escrowed with SimpleMDM, allowing admins to view and use it to unlock the encrypted drive later. This is commonly referred to as key escrow.
- Show recovery key to user: When escrow is enabled, controls whether the device user is also shown the recovery key on-screen after encryption. If escrow is disabled, the recovery key is always shown to the user, since SimpleMDM has no other way to retrieve it.
- Force FileVault to be enabled in Setup Assistant: When enabled, encryption is enforced as part of the initial Setup Assistant flow rather than waiting for the user's first login or logout. Requires macOS 14 or later.
- Attempt automatic remediation of missing FileVault recovery keys: When enabled, SimpleMDM automatically re-pushes the FileVault profile to Mac computers that don't currently have a recovery key stored in SimpleMDM. This helps recover devices that were encrypted before escrow was configured, or where the key was otherwise never captured. Only devices with no recovery key already on file are affected, so an existing key won't be needlessly rotated. Requires macOS 26 or later, Automated Device Enrollment, and a bootstrap token on file for the device; this remediation does not apply to declarative (DDM) profiles or user-channel profiles.
Viewing and rotating the recovery key
If a device's recovery key is escrowed with SimpleMDM, admins with permission to view FileVault recovery keys can reveal it from the device's detail page under "FDE Recovery Key". Admins can also issue a command to rotate a device's personal recovery key on demand, generating a new key and retiring the previous one.
Eric McCann
Was this article helpful?