You can turn on FileVault encryption on computers in your environment using the built-in functionality in Jamf Pro. FileVault is the native encryption capability built into Mac computers. Enabling it with Jamf Pro makes computers require a user's credentials to complete the boot process, ensuring that data on the computer is secure. Additionally, after a computer turns on FileVault and escrows its personal recovery key (PRK) with Jamf Pro, you can use that key to reset user passwords and access macOS recovery.
Enabling FileVault with an MDM solution is a process Apple calls "deferred enablement", which consists of the following steps when done with Jamf Pro:
Jamf Pro deploys FileVault settings to the computer.
macOS prompts the user to enter their credentials at either login or logout.
FileVault is activated, and, if using a personal recovery key, the key is escrowed with Jamf Pro.
You can also deploy a disk encryption configuration using a policy. Jamf recommends this method for environments where advanced user experience customizations or custom triggers are required. For more information, see Enabling FileVault Disk Encryption Using a Policy in the Jamf Pro Documentation.
Use the Security and Privacy payload to configure FileVault settings for managed computers.