Enabling FileVault Encryption for Mac

Jamf Now Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

FileVault is full disk encryption for Mac. When you use Jamf Now to set up FileVault, the recovery keys will be stored. This is handy if you forget the password to the Mac and still need to get access. To learn more about FileVault, see the following Apple documentation: How does FileVault work on a Mac?

Note:

If a Mac is not managed by Jamf Now prior to encryption, additional steps must be taken to store the FileVault recovery key in Jamf Now. For more information, see Generating a New FileVault Key for Escrowing with Jamf Now.

  1. Log in to Jamf Now.
  2. Click Blueprints.
  3. Select the blueprint you would like to enable the FileVault feature with.
  4. Click the Security tab.
  5. Select the Require FileVault checkbox.
  6. (Optional) Select the Display FileVault recovery keys to end users checkbox.
    Warning:Displaying FileVault keys to a user is a potential security risk. The escrowed recovery key on the device's detail page is typically sufficient.
  7. (Optional) Select the Allow FileVault to be manually disabled on Mac checkbox.
    Warning:

    Allowing end users to disable FileVault may result in the disk contents not being encrypted.

  8. Click Save Changes.
    Note:

    The user needs to log out of their user account to allow FileVault to initiate at next login.

    If a user disables FileVault on their Mac, the Mac will re-enable FileVault the next time it is restarted.