Mac Encryption Using FileVault - Elevate Documentation

Elevate Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Note:

Elevate does not currently include FileVault configuration settings; FileVault encryption must be configured using Jamf Pro.

You can turn on FileVault encryption on computers in your environment using the built-in functionality in Jamf Pro. FileVault is the native encryption capability built into Mac computers. Enabling it with Jamf Pro makes computers require a user's credentials to complete the boot process, ensuring that data on the computer is secure. Additionally, after a computer turns on FileVault and escrows its personal recovery key (PRK) with Jamf Pro, you can use that key to reset user passwords and access macOS recovery.

After FileVault has been turned on for target computers, you can use Jamf Pro to view the PRK and issue a new one.

Jamf recommends turning on FileVault by deploying a configuration profile with FileVault settings. To turn on FileVault on Mac computers, follow these general steps:

  1. Use the app switcher at the top-left of the Elevate dashboard to access Jamf Pro.

  2. In Jamf Pro, create a computer configuration profile with the Security & Privacy payload with the following FileVault settings:

    • In the Event to prompt FileVault enablement setting, select At Login.

    • Choose Personal recovery key, Institutional recovery key, or both.

    • Click Escrow Personal Recovery Key to enable the device to encrypt the personal recovery key with the provided certificate and report it to Jamf Pro.

  3. Scope the profile to a computer group created in Elevate.
For detailed information and instructions, see the following topics in the Jamf Pro Documentation: