Security · Concept · 9 min read

FileVault Disk Encryption, and Why the Disk Is Already Encrypted

Most guides describe FileVault as the thing that encrypts a Mac. On any Apple silicon or T2 machine the volume is encrypted before FileVault is touched, and what the switch changes is what protects the key: the hardware alone, or the hardware and a password.

Written by Marko Ristic, Editor Updated Sep 17, 2026
AES-XTSthe algorithm FileVault uses on internal and removable volumes
0 minto enable on an Apple silicon or T2 Mac, the data is already encrypted
2things protect the key once FileVault is on: the password and the hardware
1lost recovery key with a lost password, and the data is gone for good
Short answer

FileVault is the full-volume encryption built into macOS, and on a Mac with Apple silicon or the T2 chip the volume is already encrypted before you turn it on. With FileVault off, the volume encryption key is protected by the hardware identifier alone, so the Mac unlocks itself.

Turning it on adds the user’s password, and Apple says the change is immediate because the data is already encrypted. For a company the decisions are the recovery key, where it is escrowed, and whether device management enforces it.

  • FileVault uses the AES-XTS algorithm on internal and removable volumes
  • On Apple silicon and T2 Macs the volume is encrypted even with FileVault off
  • With FileVault off the key is protected by the hardware identifier only
  • Turning it on is immediate on those Macs, not an overnight conversion
  • MDM escrows the recovery key and can require FileVault during Setup Assistant
On this page

What it changesWhat FileVault actually changes

Apple's Platform Security guide is unusually direct about this, and it contradicts how most guides describe the feature.

Every APFS volume already has an encryption key. In Apple's words, all APFS volumes are created with a volume encryption key by default. Volume and metadata contents are encrypted with that key, which is itself wrapped with a key encryption key.

With FileVault off, the machine unlocks itself. On a Mac with Apple silicon or the T2 chip, if FileVault is not turned on during Setup Assistant, the volume is still encrypted, but the volume encryption key is protected only by the hardware identifier in the Secure Enclave.

The stored data is encrypted against someone who removes the storage; it is not protected against unauthorized access by someone who has the whole Mac, because the Mac holds everything needed to unlock it.

Turning FileVault on adds the password to the lock. Once it is on, the key encryption key is protected by a combination of the user's password and the hardware identifier, and the user's credentials are required during boot.

Apple notes that enabling it later is immediate, because the data has already been encrypted, and that an anti-replay mechanism prevents the old hardware-only key from being used afterwards.

That last point is worth keeping, because the folklore that FileVault takes hours and slows the machine comes from Intel Macs without a T2 chip, where turning it on really did convert the disk.

Where the keys live. On Apple silicon and T2 Macs all FileVault key handling happens in the Secure Enclave, and encryption keys are never directly exposed to the CPU. Removable storage does not get that treatment: Apple says encryption of removable devices is performed the same way as on an Intel Mac without a T2 chip.

Key hierarchyThe key hierarchy, and the four things it buys

Apple lists four goals for the arrangement of keys, and each one answers a question people actually ask about FileVault disk encryption.

It requires the user's password to decrypt. That is the protection everyone expects.

It resists a brute-force attack against storage removed from the Mac. Pulling the chip does not help, because the hardware identifier that helps protect the key never leaves the Secure Enclave of that machine.

It makes wiping fast and final. Apple describes it as a swift and secure method for wiping content through deletion of the necessary cryptographic material: destroy the keys and the volume is unreadable, with no overwrite pass needed.

It lets a password change without re-encrypting. Changing the password rewraps the key rather than rewriting the disk, which is why a password change is instant.

On one MacTurning FileVault on, on one Mac

Apple's own user guide gives the steps, and two details in it are worth reading before anyone clicks.

The steps. Choose the Apple menu, then System Settings, click Privacy and Security in the sidebar, then click FileVault, then turn it on. You may be asked for your password. You must be an administrator of that Mac to set it up.

The unlock choice. macOS asks how you want to unlock the startup disk if the login password is ever forgotten: through an iCloud account, or with a recovery key it generates for you.

Apple's guidance on the key is blunt: keep a copy somewhere other than the encrypted disk, and not in the same physical location as the Mac. Its warning is blunter still, that if the login password and the recovery key are both lost, the files and settings are lost forever.

Other users on the machine. Their data is encrypted too, and each user unlocks the disk with their own login password. If an Enable Users button appears, each user's password has to be entered before that person can unlock the encrypted disk.

For a company, the iCloud option is the one to think about: it moves the unlock path to a personal Apple account rather than to something the business controls, which is why managed deployments escrow a recovery key instead.

Recovery keyThe recovery key, which is the part that bites

If the password is lost and there is no other unlock path, the data is gone. That is the point of the design, and it makes the recovery key the most consequential decision in a FileVault rollout.

A personal recovery key is generated when a user turns FileVault on themselves. Written on a sticky note it defeats the purpose, and lost with the password it ends the conversation.

An escrowed key is the managed answer. A device management service can specify which certificate is used to asymmetrically encrypt the recovery key for escrow, so the key reaches the MDM encrypted rather than in the clear.

Who can even unlock the volume. Apple's requirement is specific: a user enabled to unlock storage on APFS volumes needs a secure token, and on a Mac with Apple silicon they must be a volume owner. This is the rule behind the classic support case where an administrator account exists on the Mac but cannot unlock it after a restart.

Test the recovery before trusting it. A key in an MDM nobody has ever used to unlock a Mac is an assumption. Unlock one machine with it, in the same week the rollout happens, and write down which users on that Mac could unlock the drive and which could not.

Across a fleetTurning FileVault on across a fleet

Two managed paths exist, and they suit different fleets.

Deferred enablement. Managing FileVault through a device management service is what Apple calls deferred enablement: the profile arrives, and the user is prompted at a logout or login event.

The service can set how many times the user may defer, whether to prompt at logout as well as login, and whether the recovery key is shown to the user at all.

Enforcing it at setup. With the ForceEnableInSetupAssistant key, Macs can be required to turn FileVault on during Setup Assistant, which Apple describes as ensuring that internal storage in managed Macs is always encrypted before it is used.

For new machines that arrive enrolled through Automated Device Enrollment, this is the cleanest option, because no machine ever exists in the unenforced state.

What an RMM alone cannot do. Enabling FileVault, escrowing the key and enforcing it are device management functions, not agent functions, and the same split shows up everywhere else in RMM for Mac. An RMM agent can report whether FileVault is on, and that reporting is how most MSPs discover the gap, but the enforcement belongs to the MDM.

Against BitLockerFileVault and BitLocker, briefly

The two are the same category and differ in where the trust sits.

Disk encryption is one security control among several, and both platforms implement it the same way at a distance. Windows uses BitLocker with a recovery key and a TPM; macOS uses FileVault with the Secure Enclave.

Both encrypt the volume, both hold a key in dedicated hardware, and both hand the administrator the same problem: the recovery key has to be escrowed somewhere the company can reach and an attacker cannot. On a Mac the added wrinkle is the secure token and volume owner rule, which has no direct Windows equivalent.

PitfallsWhere people go wrong

Assuming an unencrypted Mac is unencrypted. On Apple silicon and T2 hardware the volume is encrypted either way. The question is whether the key needs a password, and that is what a compliance report should be asking.

Leaving the recovery key with the user. The one person who forgets the password is the one holding the key.

Enabling it without a volume owner. A management account without a secure token cannot unlock the disk, and the discovery usually happens during an incident.

Believing it protects a running Mac. Disk encryption protects information at rest. A machine that is awake and logged in is decrypted for anyone sitting at it, so access control does the rest: screen locks, multi-factor authentication and session timeouts.

Skipping it because the Mac is desktop-bound. A stolen desktop leaves the building as easily as a laptop, and the drive is the part that matters. Every Mac in the fleet should show FileVault enabled, not just the portable devices.

Counting compliance from the MDM alone. The device management service shows the policy. Whether every Mac actually reports FileVault enabled, with a key escrowed, is a separate report worth reading each month, and it is the report an auditor asks for.

WHAT FILEVAULT CHANGES ON A MODERN MACVOLUME AND METADATA, ENCRYPTEDAlways on Apple silicon and T2 Macs. AES-XTS, keys in the Secure Enclave.FILEVAULT OFFFILEVAULT ONHARDWARE IDENTIFIER ONLYUSER PASSWORD + HARDWARE IDthe Mac unlocks itselfcredentials required at bootKEY ENCRYPTION KEYKEY ENCRYPTION KEYwraps the volume key
The volume is encrypted either way on a modern Mac. FileVault changes what protects the key that unwraps it, and that is the whole difference.

ComparisonWhat changes when FileVault is turned on

CriterionFileVault offFileVault on
Volume encryptedYes, on Apple silicon and T2Yes
What protects the keyHardware identifier onlyPassword and hardware identifier
Mac stolen with the disk insideUnlocks itselfNeeds the password
Storage chip removedUnreadableUnreadable
Password required at bootNoYes
Recovery key existsNoYes, escrow it
Time to switch onImmediate, data already encrypted
Wipe is instantYesYes

The third row is the whole argument. Everything else follows from it.

FAQFrequently asked questions

What is FileVault disk encryption?

The full-volume encryption built into macOS. It uses the AES-XTS algorithm and, on Apple silicon and T2 Macs, keeps all key handling inside the Secure Enclave, where the keys are never exposed to the CPU.

Is my Mac encrypted without FileVault?

On Apple silicon and T2 Macs, yes, the volume is encrypted, but the key is protected only by the hardware identifier, so the Mac can unlock itself. FileVault adds the user's password to that protection.

Does turning on FileVault take hours?

Not on Apple silicon or T2 Macs. Apple says the process is immediate because the data has already been encrypted. Older Intel Macs without a T2 chip did have to convert the disk.

Does FileVault slow down a Mac?

The encryption runs in dedicated hardware, the AES engine connected to the Secure Enclave, on Apple silicon and T2 Macs. It is also why changing the password does not re-encrypt the volume: Apple lists that as one of the goals of the key hierarchy.

What happens if I lose the password and the recovery key?

The data is unrecoverable. That is the design, not a bug, which is why the recovery key belongs in an escrow the company controls.

How does an MDM escrow the FileVault key?

The device management service specifies a certificate, and the recovery key is asymmetrically encrypted to that certificate before it is escrowed, so it does not travel in the clear.

What is deferred enablement?

Apple's term for managing FileVault through a device management service: the policy is delivered, and FileVault is turned on at a user logout or login. The service can control how many deferrals a user gets and whether the key is shown to them.

Can I require FileVault on a new Mac before anyone uses it?

Yes. The ForceEnableInSetupAssistant key requires FileVault to be turned on during Setup Assistant, so managed Macs are always encrypted with a password before the storage is used.

Why can my admin account not unlock the Mac?

Unlocking an APFS volume requires a secure token, and on Apple silicon the account must also be a volume owner. An account created without one can administer the Mac and still not unlock it at boot.

Does FileVault protect a Mac that is switched on?

No. It protects data at rest. Once the Mac is unlocked, the data is available to whoever is at the keyboard, which is a job for screen locks and session timeouts.

Is FileVault enough for compliance?

It satisfies the encryption-at-rest control that most security frameworks ask for, when it is enabled and the key is escrowed, and it says nothing about the access controls or the rest of the system. What auditors ask for next is evidence: a report showing every Mac with FileVault on, and a key the company can retrieve.

Does FileVault encrypt external drives?

It can encrypt removable storage devices, and Apple notes that they do not use the Secure Enclave for it; the encryption is performed the way an Intel Mac without a T2 chip does it, in software.

Is FileVault the only option for Mac full disk encryption?

For the startup disk, FileVault is the built in and supported way to do Mac full disk encryption, and there is little reason to use anything else. On Macs with Apple silicon or a T2 chip the data is always encrypted in hardware, and turning on FileVault ties the key to your password.

Read next · Cryptography The BitLocker Recovery Key, and Why the Screen Appeared The same problem on Windows: where the recovery key lives and who can reach it. Open this next10 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.