Enabling FileVault Disk Encryption

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

You can turn on FileVault encryption on computers in your environment using the built-in functionality in Jamf Pro. FileVault is the native encryption capability built into Mac computers. Enabling it with Jamf Pro makes computers require a user's credentials to complete the boot process, ensuring that data on the computer is secure. Additionally, after a computer turns on FileVault and escrows its personal recovery key (PRK) with Jamf Pro, you can use that key to reset user passwords and access macOS recovery.

Enabling FileVault with an MDM solution is a process Apple calls "deferred enablement", which consists of the following steps when done with Jamf Pro:

  1. Jamf Pro deploys FileVault settings to the computer.

  2. macOS prompts the user to enter their credentials at either login or logout.

  3. FileVault is activated, and, if using a personal recovery key, the key is escrowed with Jamf Pro.

When you enable FileVault disk encryption by deploying a configuration profile from Jamf Pro, the settings install immediately, prompting the end user to enable FileVault either at login or logout. If configured to use a personal recovery key, the computer escrows the key with Jamf Pro at the time of the next inventory update.
Note:

You can also deploy a disk encryption configuration using a policy. Jamf recommends this method for environments where advanced user experience customizations or custom triggers are required. For more information, see Enabling FileVault Disk Encryption Using a Policy in the Jamf Pro Documentation.

Use the Security and Privacy payload to configure FileVault settings for managed computers.

  1. On the Configuration Profiles page, do one of the following:
    • Click New to create a new configuration profile.

    • Select an existing configuration profile and click Edit .

  2. Click the Security and Privacy payload, and then click FileVault.
  3. Click the toggle to include the Enable FileVault setting.
  4. Jamf recommends using the following settings:
    • Enable FileVaultInclude
      • Event to prompt FileVault enablementAt Login
      • Allow users to bypass FileVault prompts at loginRequire on the next login
      • Force Enable In Setup AssistantInclude
        Important:

        Configuration profiles configured with the Force Enable In Setup Assistant setting enabled must be deployed as part of a PreStage enrollment in order to turn on FileVault for managed computers. In addition, target computers must have macOS 14.0 or later. If the Account Settings payload in the PreStage enrollment is configured to create an additional local user account, the Local User Account Type must be set to Administrator Account. For more information on how to include a configuration profile in a PreStage Enrollment, see "Installing Configuration Profiles during Automated Device Enrollment" in Automated Device Enrollment for Computers.

      • Recovery keysPersonal recovery key
        Note:

        Institutional recovery keys are not recommended. For more information, see Manage FileVault with mobile device management in Apple Platform Deployment.

      • Display personal recovery key to userHide
    • User adjustment of FileVault optionsPrevent FileVault from being disabled
    • Require user to unlock FileVault after hibernationDisable
    • Secure Token User PromptHide
    • Escrow Personal Recovery KeyInclude
      • Encryption MethodAutomatic
      • Escrow Location DescriptionJamf Pro
  5. Click the Scope tab and configure the scope of the configuration profile.

    You can create a FileVault-specific smart group to use as the scope target. For more information, see Recommended Smart Computer Group Criteria.

  6. Click Save .
After the FileVault settings have been saved, the result will look similar to the following screenshot: