Resolving an "Unable to Change Key" FileVault Error

Jamf Now Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

If entering the sudo fdesetup changerecovery -personal command in Terminal results in an alert, you can manually disable and then re-enable FileVault on the Mac.

  1. Manually disable FileVault on the Mac. For instructions, see Turn off FileVault on Mac in the macOS User Guide.
  2. Log out of the Mac by clicking the Apple logo and selecting Log Out.
  3. After you have logged out, enter your Mac password when prompted to enable FileVault.
  4. Log in to the Jamf Now managed local user account on the Mac.
  5. Log in to Jamf Now.
  6. Click Devices, and then select the Mac.
  7. Click Sync in the upper-right corner.

The Mac will report the FileVault recovery key to Jamf Now the next time it syncs with Jamf Now.