Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

A company MacBook gets left in a taxi, and someone asks whether the data on it is safe. On a Mac, the answer depends on one setting and one string of characters that rarely gets written down. Here's what FileVault does, what it adds on modern Macs, and how to run it across a fleet without locking anyone out.

What Is FileVault?

FileVault is the full-disk encryption built into macOS. It encrypts the whole startup volume with the AES-XTS algorithm and ties the encryption key to the user's login password, so the data is unreadable to anyone who doesn't know that password or hold the recovery key. On Macs with Apple silicon or a T2 chip, all FileVault key handling happens inside the Secure Enclave, and the keys never reach the CPU.

It's the Mac counterpart to BitLocker on Windows. Same job, same trade-off: strong protection for a lost laptop, and a hard lockout for anyone who loses both the password and the recovery key.

Microsoft's Intune documentation states the cipher plainly: XTS-AES 128-bit, fixed by Apple, and not something you can change to 256-bit from macOS or an MDM.

Already Encrypted? What FileVault Adds on Apple Silicon

This part catches people out. On a Mac with Apple silicon or a T2 chip, the internal drive is encrypted even when FileVault is off.

Apple's Platform Security guide explains the difference. With FileVault off, the volume is still encrypted, but the key is protected only by the hardware UID in the Secure Enclave. Turn FileVault on, and the key is protected by the hardware UID and the user's password together.

So the useful question is whether unlocking the disk needs the password or just the hardware. For a laptop that leaves the office, you want the password in that equation.

This r/mac thread asks the question users ask first, and the replies show how easy it is to get half right.

The Recovery Key Is the Whole Game

When FileVault turns on, macOS creates a personal recovery key and shows it once. It's the backup way in: it unlocks the Mac from recoveryOS or at startup when the password is gone. Lose the password and the key, and nobody gets the data back, including Apple.

On one personal Mac, the user writes the key down or stores it with their Apple Account. On a company fleet, that's not good enough. The key belongs in your device management system, where IT can find it when a user can't.

That process is called escrow. Apple's deployment guide describes how it works: the MDM gives the Mac a certificate, the Mac encrypts the recovery key with it, and only the MDM can decrypt it. You can also hide the key from the user during enablement, so the only copy lives with IT.

Intune adds two rules worth knowing. Admins can view the key only on devices marked Corporate, while Personal devices keep it self-service through the Company Portal. And every time someone clicks Show Recovery Key, the access lands in the Entra audit log. Keys can also rotate automatically, on a schedule of 1 to 12 months.

Turn It On Across a Fleet

Pushing FileVault by policy beats asking users to click a toggle. In Intune there are two routes: Endpoint security, then Disk encryption, then a macOS FileVault profile, or the Settings Catalog for more options.

New Macs are the easy case. On macOS 14 and later, a Mac enrolled through Apple Business Manager can turn FileVault on during Setup Assistant, before the user ever reaches the desktop. On macOS 14.4 that needs the Defer setting enabled, a detail that's easy to miss. On macOS 26.4 and later, Apple says the MDM can use the bootstrap token to grant the user a secure token and switch FileVault on straight away.

Macs that users encrypted themselves are the awkward case. The MDM doesn't have their key, so it can't manage them. You have two ways to fix it:

  1. Upload the key. The user enters their current recovery key in the Company Portal, and Intune rotates it to a new escrowed key.
  2. Generate a new one. The user runs sudo fdesetup changerecovery -personal in Terminal, and the Mac escrows the new key at its next check-in.

This r/Intune thread is the classic symptom: policy applied, disk encrypted, key missing from the console. The replies point at exactly this pre-encrypted case, plus plain check-in delay.

Picking the MDM itself is a separate decision. Our comparison of Apple MDM for business covers the options if you're managing Macs across several clients.

When a User Is Locked Out

The call usually comes on a Monday. Someone changed their password on Friday, forgot it over the weekend, and the Mac is asking for FileVault before it will even show the desktop.

If the key is escrowed, this is a short ticket. The user can pull it themselves from the Company Portal website on any other device: Devices, pick the Mac, Get recovery key. If they can't, a help desk tech with the right permission looks it up in the Intune admin center under the device's recovery keys, and the lookup is logged.

The user types the recovery key at the FileVault prompt and resets their password. Rotate the key afterwards, because it has now been read out over the phone. Intune can do that per device from the device overview, or on the schedule you set in policy.

If the key was never escrowed, the ticket changes shape. Without the password or the key, the data on that Mac is gone, and the fix is an erase and reinstall from recoveryOS. That's why the escrow check belongs in onboarding, not in the lockout call.

The permission to see and rotate keys is worth scoping tightly. In Intune it sits under Remote tasks, as the Rotate FileVault key right, and it's included in the built-in Help Desk Operator and Endpoint Security Administrator roles. Give it to the people who take lockout calls, and nobody else.

What FileVault Doesn't Protect

FileVault protects data at rest. Once the user logs in, the disk is unlocked, and everything on it is as readable as it would be without encryption.

That leaves gaps worth naming. It won't stop malware running as the logged-in user. It won't protect copies in iCloud, OneDrive or email. It doesn't cover an external drive unless that drive is encrypted separately. And a Mac left asleep and unlocked is an open Mac, so pair FileVault with a short screen-lock timeout and the ability to wipe a lost device remotely.

This short explainer from Moonlock by MacPaw walks through what FileVault does and whether to turn it on, from the user's side of the screen.

Checking It Stays On

The job is knowing FileVault is still on across every Mac, not just that it was turned on once. A compliance policy that requires encryption lets you block company apps on any Mac that drifts, and an encryption report shows which devices have a key escrowed and which don't.

OpenFrame, Flamingo's open, AI-native infrastructure layer for IT and security, runs osquery-based policy checks through Fleet, with each device marked compliant or non-compliant. A check for FileVault status turns "is it on?" into a list you can act on. Our Fleet MDM review covers how that query layer works.

Encrypt, Escrow, Check

On a modern Mac, the disk is encrypted from day one. FileVault is what makes the password part of the lock, and the recovery key is what keeps IT from becoming part of the problem.

Turn it on by policy, escrow every key, and check that it stays on. For the wider Mac management picture, the Apple MDM comparison above is the next read.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

FileVault

Not in a way users notice on Macs with Apple silicon or a T2 chip. Encryption runs in dedicated hardware, and the disk on those Macs is encrypted whether FileVault is on or off; FileVault changes how the key is protected, not how data is read and written.
On a personal desktop that never leaves the house, it is a choice. On a company laptop, keep it on: without FileVault the disk key is protected only by the hardware, so the password no longer stands between a thief and the data.
If you still know your password, nothing changes, and you can generate a new key with fdesetup or through your MDM. If both the password and the key are lost and no copy is escrowed, the data cannot be recovered and the Mac has to be erased.
They do the same job on different platforms. FileVault encrypts macOS startup disks and BitLocker encrypts Windows drives; both use a recovery key that businesses should escrow to their device management system.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
In the cloud, on US soil. Your data stays stateside.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.