Updated: October 2026
A company MacBook gets left in a taxi, and someone asks whether the data on it is safe. On a Mac, the answer depends on one setting and one string of characters that rarely gets written down. Here's what FileVault does, what it adds on modern Macs, and how to run it across a fleet without locking anyone out.
What Is FileVault?
FileVault is the full-disk encryption built into macOS. It encrypts the whole startup volume with the AES-XTS algorithm and ties the encryption key to the user's login password, so the data is unreadable to anyone who doesn't know that password or hold the recovery key. On Macs with Apple silicon or a T2 chip, all FileVault key handling happens inside the Secure Enclave, and the keys never reach the CPU.
It's the Mac counterpart to BitLocker on Windows. Same job, same trade-off: strong protection for a lost laptop, and a hard lockout for anyone who loses both the password and the recovery key.
Microsoft's Intune documentation states the cipher plainly: XTS-AES 128-bit, fixed by Apple, and not something you can change to 256-bit from macOS or an MDM.
Already Encrypted? What FileVault Adds on Apple Silicon
This part catches people out. On a Mac with Apple silicon or a T2 chip, the internal drive is encrypted even when FileVault is off.
Apple's Platform Security guide explains the difference. With FileVault off, the volume is still encrypted, but the key is protected only by the hardware UID in the Secure Enclave. Turn FileVault on, and the key is protected by the hardware UID and the user's password together.
So the useful question is whether unlocking the disk needs the password or just the hardware. For a laptop that leaves the office, you want the password in that equation.
This r/mac thread asks the question users ask first, and the replies show how easy it is to get half right.
The Recovery Key Is the Whole Game
When FileVault turns on, macOS creates a personal recovery key and shows it once. It's the backup way in: it unlocks the Mac from recoveryOS or at startup when the password is gone. Lose the password and the key, and nobody gets the data back, including Apple.
On one personal Mac, the user writes the key down or stores it with their Apple Account. On a company fleet, that's not good enough. The key belongs in your device management system, where IT can find it when a user can't.
That process is called escrow. Apple's deployment guide describes how it works: the MDM gives the Mac a certificate, the Mac encrypts the recovery key with it, and only the MDM can decrypt it. You can also hide the key from the user during enablement, so the only copy lives with IT.
Intune adds two rules worth knowing. Admins can view the key only on devices marked Corporate, while Personal devices keep it self-service through the Company Portal. And every time someone clicks Show Recovery Key, the access lands in the Entra audit log. Keys can also rotate automatically, on a schedule of 1 to 12 months.
Turn It On Across a Fleet
Pushing FileVault by policy beats asking users to click a toggle. In Intune there are two routes: Endpoint security, then Disk encryption, then a macOS FileVault profile, or the Settings Catalog for more options.
New Macs are the easy case. On macOS 14 and later, a Mac enrolled through Apple Business Manager can turn FileVault on during Setup Assistant, before the user ever reaches the desktop. On macOS 14.4 that needs the Defer setting enabled, a detail that's easy to miss. On macOS 26.4 and later, Apple says the MDM can use the bootstrap token to grant the user a secure token and switch FileVault on straight away.
Macs that users encrypted themselves are the awkward case. The MDM doesn't have their key, so it can't manage them. You have two ways to fix it:
- Upload the key. The user enters their current recovery key in the Company Portal, and Intune rotates it to a new escrowed key.
- Generate a new one. The user runs
sudo fdesetup changerecovery -personalin Terminal, and the Mac escrows the new key at its next check-in.
This r/Intune thread is the classic symptom: policy applied, disk encrypted, key missing from the console. The replies point at exactly this pre-encrypted case, plus plain check-in delay.
Picking the MDM itself is a separate decision. Our comparison of Apple MDM for business covers the options if you're managing Macs across several clients.
When a User Is Locked Out
The call usually comes on a Monday. Someone changed their password on Friday, forgot it over the weekend, and the Mac is asking for FileVault before it will even show the desktop.
If the key is escrowed, this is a short ticket. The user can pull it themselves from the Company Portal website on any other device: Devices, pick the Mac, Get recovery key. If they can't, a help desk tech with the right permission looks it up in the Intune admin center under the device's recovery keys, and the lookup is logged.
The user types the recovery key at the FileVault prompt and resets their password. Rotate the key afterwards, because it has now been read out over the phone. Intune can do that per device from the device overview, or on the schedule you set in policy.
If the key was never escrowed, the ticket changes shape. Without the password or the key, the data on that Mac is gone, and the fix is an erase and reinstall from recoveryOS. That's why the escrow check belongs in onboarding, not in the lockout call.
The permission to see and rotate keys is worth scoping tightly. In Intune it sits under Remote tasks, as the Rotate FileVault key right, and it's included in the built-in Help Desk Operator and Endpoint Security Administrator roles. Give it to the people who take lockout calls, and nobody else.
What FileVault Doesn't Protect
FileVault protects data at rest. Once the user logs in, the disk is unlocked, and everything on it is as readable as it would be without encryption.
That leaves gaps worth naming. It won't stop malware running as the logged-in user. It won't protect copies in iCloud, OneDrive or email. It doesn't cover an external drive unless that drive is encrypted separately. And a Mac left asleep and unlocked is an open Mac, so pair FileVault with a short screen-lock timeout and the ability to wipe a lost device remotely.
This short explainer from Moonlock by MacPaw walks through what FileVault does and whether to turn it on, from the user's side of the screen.
Checking It Stays On
The job is knowing FileVault is still on across every Mac, not just that it was turned on once. A compliance policy that requires encryption lets you block company apps on any Mac that drifts, and an encryption report shows which devices have a key escrowed and which don't.
OpenFrame, Flamingo's open, AI-native infrastructure layer for IT and security, runs osquery-based policy checks through Fleet, with each device marked compliant or non-compliant. A check for FileVault status turns "is it on?" into a list you can act on. Our Fleet MDM review covers how that query layer works.
Encrypt, Escrow, Check
On a modern Mac, the disk is encrypted from day one. FileVault is what makes the password part of the lock, and the recovery key is what keeps IT from becoming part of the problem.
Turn it on by policy, escrow every key, and check that it stays on. For the wider Mac management picture, the Apple MDM comparison above is the next read.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
