Administering FileVault on Computers

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Requirements

To administer FileVault on computers, you need:

  • Computers with macOS 10.7 or later

  • A device group of computers you want to administer FileVault on (For more information, see Device Groups.)

  • A recovery key

    Note:

    You must choose between a personal or institutional recovery key for your FileVault configuration. Personal recovery keys are uniquely generated for each computer and can be automatically escrowed to Jamf School to use to access the encrypted disk or reset a user's password. Personal recovery keys are the recommended recovery key type. Institutional recovery keys can be used to recover data on Intel-based computers and should not be used for computers with Apple silicon. For more information about institutional recovery keys, see the How to use institutional recovery keys with Intel-based Macs article from Apple's support website.

  • A secure token (For more information, see Use secure token, bootstrap token, and volume ownership in deployments in Apple Platform Deployment.)

Warning:

Institutional recovery keys present a greater inherent security concern because they can be used for multiple computers. They also have more limited functionality on Mac computers with Apple silicon, and Apple no longer recommends them for institutional management in general. For most environments, Jamf recommends using personal recovery keys.

  1. In Jamf School, navigate to Profiles > Overview in the sidebar.
  2. Click + Create Profile.
  3. Select the macOS operating system.
  4. Select the Device Enrollment enrollment type.
  5. Enter a name in the Profile name field and configure the additional settings as needed, including the removal policy and time filter.
  6. Click Finish.
  7. (Institutional recovery key only) In the list of payloads on the left side of the pane, locate the General payload category and click the Certificates payload, then click Choose file and upload the institutional recovery key certificate file (.cer).
  8. In the list of payloads on the left side of the pane, locate the macOS payload category and click the FileVault payload.
  9. Click Configure to configure the settings, including the following:
    1. Ensure the Enable FileVault checkbox is selected.
    2. Choose the recovery key type.
    3. (Institutional recovery key only) Choose the certificate to use from the Certificate pop-up menu.
    4. (Personal recovery key only) To ensure the personal recovery key is stored in Jamf School, select the Enable Personal Recovery Key Escrow checkbox. This allows you to view the personal recovery key in the device details.
      Note:

      (macOS 14–14.4 only) To enable Personal Recovery Key Escrow during Automated Device Enrollment, the user must create an administrator account while proceeding through Setup Assistant. For more information, see Creating an Automated Device Enrollment Profile.

  10. In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
  11. Configure the scope of the profile by clicking the + icon and adding device groups to the profile scope using the pop-up menu.
  12. Click the Settings icon on the right side of the page, and do one of the following:
    • To install the profile on devices automatically, click Change to automatic installation for all groups.

    • To allow users to install the profile themselves, click Change to on-demand installation for all groups. The profile will be available for users to install in the Jamf Teacher or Jamf School Student apps.

  13. Click Save.

The new profile appears in the Profiles overview.

If you want to access data or unlock user passwords, you can use the recovery key. For more information, see the following: