Creating and Exporting an Institutional Recovery Key

Jamf Pro Documentation 11.30.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.30.0
ft:locale
en-US
vrm_version
11.30.0

Warning:

Institutional recovery keys present a greater inherent security concern because they can be used for multiple computers. They also have more limited functionality on Mac computers with Apple silicon, and Apple no longer recommends them for institutional management in general. For most environments, Jamf recommends using personal recovery keys.

Note:

If you plan to use only personal recovery keys in your environment, you do not need to perform this workflow.

To use an institutional recovery key, you must first create and export a recovery key using Keychain Access.

You can export the recovery key with or without the private key. Exporting with the private key allows you to store it in Jamf Pro. If you export without the private key, you must store it in a secure location so you can access it when needed.

Note:

You cannot use an institutional recovery key with a private key to activate FileVault Disk Encryption using a configuration profile in Jamf Pro. You must create and deploy the disk encryption configuration using a policy in Jamf Pro.