Back to blog
EncryptionPublished on July 21, 20268 min read

FileVault on Mac via Intune with recovery key

Enable FileVault encryption on your Macs via Intune with recovery-key escrow, so you never lose access to an encrypted device again, with no PowerShell.

FileVault is Apple's full-disk encryption, the equivalent of BitLocker on the Mac. Without it, a stolen Mac hands over all its data to anyone who can pull the drive or boot from another system. Turning it on via Intune is simple; the part that makes all the difference is escrowing the recovery key, so you never lose access to an encrypted device.

Many organisations enable FileVault but forget this escrow, and find out the day an employee leaves without sharing their password, or when a login becomes inaccessible. The disk is then encrypted and completely unusable. Configured properly, FileVault protects your data without ever locking you out yourself: it is this combination of strong encryption and a controlled fallback that separates a professional deployment from a switch simply flipped on each machine.

Why key escrow is essential

When FileVault is enabled, macOS generates a recovery key: the only way to unlock the disk if the user forgets their login or leaves the company. Without escrow, that key is lost and the data becomes permanently inaccessible, with no recourse at all. There is no back door and no vendor reset; the encryption that protects you from a thief protects the data from you just as effectively once the key is gone.

  • The recovery key is stored, or escrowed, securely in Intune.
  • An authorised administrator can retrieve it to unlock a locked Mac.
  • The user has nothing to write down or keep themselves, which avoids keys scrawled on a sticky note.
  • A departing employee no longer blocks access to the machine.
An escrowed recovery key avoids any permanently locked Mac.

Enable FileVault through Intune

FileVault is configured in a Disk encryption profile (Endpoint Security) targeting macOS devices. The important settings are few, but their combination determines both security and day-to-day comfort for users.

  1. 1Enable FileVault and require activation at user sign-in.
  2. 2Enable escrow of the personal recovery key to Intune.
  3. 3Set a grace period and a number of allowed deferrals before activation is enforced.
  4. 4Make FileVault a requirement in your macOS compliance policy.
  5. 5Pair that compliance with Conditional Access to block unencrypted Macs.

Activation often asks the user to log out to start encryption; it then continues in the background without disrupting work. A grace period avoids forcing that logout in the middle of a task. Once FileVault is on and the key escrowed, the device can be marked compliant and allowed by Conditional Access.

Think about the device lifecycle too. When a Mac changes hands or comes back to IT, the escrowed recovery key lets you unlock it, wipe it cleanly and reassign it without losing access. Without that escrow, an encrypted Mac returned by a former employee who has forgotten their password is headed for a full erase, sometimes impossible without the key. Escrow therefore turns FileVault into a management asset, not just a security measure, and saves you from writing off perfectly good hardware.

Retrieve and rotate the key

Once FileVault is active, the recovery key can be viewed on the device record in the Intune portal. When needed, an authorised administrator copies it to unlock the Mac, then can request generation of a new key so the old one, now known, is no longer usable.

Rotating the key after each use is good practice: it limits the window during which a disclosed key stays valid. Document who is allowed to view these keys, because that access is equivalent to being able to decrypt any Mac in the fleet. A log of key views strengthens the traceability of this sensitive privilege even further, and reviewing it periodically is a small habit that pays off during an audit.

Common mistakes to avoid

FileVault is reliable, but a few oversights come up often and turn a good measure into a source of problems.

  • Enabling FileVault without key escrow, and ending up with an inaccessible Mac at the first forgotten password.
  • Enforcing activation with no grace period, interrupting users mid-task.
  • Failing to restrict or log access to recovery keys, when that access can decrypt the entire fleet.
  • Forgetting to pair FileVault with compliance and Conditional Access, letting unencrypted Macs reach resources.

A pillar of macOS compliance

Disk encryption is an explicit requirement of GDPR, ISO 27001 and NIS2 to protect data at rest. Pairing FileVault with a compliance policy and Conditional Access ensures an unencrypted Mac cannot reach company resources until it complies. If an encrypted Mac is stolen, the data stays protected, which sharply reduces the scope of the incident and the reporting obligations that follow.

An unencrypted Mac is refused by Conditional Access.

Track encryption state across the fleet

Enabling FileVault is not enough: you still need to confirm that encryption actually finished on each machine and that the key was genuinely escrowed. A Mac can show the policy as received while the user has not yet restarted to start encryption. The Intune reports give this visibility, provided you consult them regularly rather than just once after the rollout.

  • Check each device's encryption status in Intune's disk encryption reports.
  • Confirm the recovery key is present on the device record before considering the machine protected.
  • Identify Macs still waiting for activation and chase their users.
  • Cross-reference this state with your compliance policy to spot unencrypted devices that still reach resources.

This monitoring turns intent into evidence. On the day of an audit or an incident, being able to show the exact proportion of encrypted Macs, with escrowed keys to back it up, is far better than a general claim. It is also what warns you early when a batch of new machines has slipped past the policy, before an unprotected device is lost or stolen.

How AuPoint secures FileVault

The real risk when configuring FileVault by hand is forgetting escrow and ending up with an inaccessible Mac. AuPoint is a SaaS that makes Intune security and compliance easy, with no PowerShell. It provides a ready-made FileVault policy with key escrow on by default, an impact preview before applying and one-click rollback, so you can encrypt your Macs safely.

Frequently asked questions

Does FileVault encryption slow the Mac down?

No. On recent Macs, encryption is hardware-accelerated and the day-to-day performance impact is imperceptible. Only the very first encryption phase runs in the background, without blocking the user, and on Apple silicon the data is protected from the moment the Mac is set up.

What if a user refuses to enable FileVault?

On a supervised Mac (ADE), activation can be enforced with no option to decline. In BYOD, FileVault becomes a compliance requirement: until it is active, the Mac is non-compliant and Conditional Access refuses it access to company resources, which is usually enough to prompt the user to turn it on promptly.

Where is the recovery key stored?

The personal key is escrowed securely in Intune and viewable on the device record by authorised administrators. The user therefore does not need to keep it themselves, and there is no separate password vault to maintain outside your existing Microsoft tooling.

Does FileVault also encrypt the Mac's external drives?

No, FileVault protects the Mac's internal startup disk. For an external drive, macOS offers a separate volume encryption that the user enables from the Finder. If your users handle sensitive removable media, plan a dedicated guideline, because those volumes are not covered by the system disk's FileVault policy.

Connect your Microsoft tenant to AuPoint and encrypt your Macs with FileVault in minutes, key escrow included, with an impact preview and reversibility, no PowerShell. Start free at aupoint.io.

Secure your tenant in 15 minutes

Free trial