FileVault is the full-volume encryption built into macOS, and on a Mac with Apple silicon or the T2 chip the volume is already encrypted before you turn it on. With FileVault off, the volume encryption key is protected by the hardware identifier alone, so the Mac unlocks itself.
Turning it on adds the user’s password, and Apple says the change is immediate because the data is already encrypted. For a company the decisions are the recovery key, where it is escrowed, and whether device management enforces it.
- FileVault uses the AES-XTS algorithm on internal and removable volumes
- On Apple silicon and T2 Macs the volume is encrypted even with FileVault off
- With FileVault off the key is protected by the hardware identifier only
- Turning it on is immediate on those Macs, not an overnight conversion
- MDM escrows the recovery key and can require FileVault during Setup Assistant
On this page
What it changesWhat FileVault actually changes
Apple's Platform Security guide is unusually direct about this, and it contradicts how most guides describe the feature.
Every APFS volume already has an encryption key. In Apple's words, all APFS volumes are created with a volume encryption key by default. Volume and metadata contents are encrypted with that key, which is itself wrapped with a key encryption key.
With FileVault off, the machine unlocks itself. On a Mac with Apple silicon or the T2 chip, if FileVault is not turned on during Setup Assistant, the volume is still encrypted, but the volume encryption key is protected only by the hardware identifier in the Secure Enclave.
The stored data is encrypted against someone who removes the storage; it is not protected against unauthorized access by someone who has the whole Mac, because the Mac holds everything needed to unlock it.
Turning FileVault on adds the password to the lock. Once it is on, the key encryption key is protected by a combination of the user's password and the hardware identifier, and the user's credentials are required during boot.
Apple notes that enabling it later is immediate, because the data has already been encrypted, and that an anti-replay mechanism prevents the old hardware-only key from being used afterwards.
That last point is worth keeping, because the folklore that FileVault takes hours and slows the machine comes from Intel Macs without a T2 chip, where turning it on really did convert the disk.
Where the keys live. On Apple silicon and T2 Macs all FileVault key handling happens in the Secure Enclave, and encryption keys are never directly exposed to the CPU. Removable storage does not get that treatment: Apple says encryption of removable devices is performed the same way as on an Intel Mac without a T2 chip.
Key hierarchyThe key hierarchy, and the four things it buys
Apple lists four goals for the arrangement of keys, and each one answers a question people actually ask about FileVault disk encryption.
It requires the user's password to decrypt. That is the protection everyone expects.
It resists a brute-force attack against storage removed from the Mac. Pulling the chip does not help, because the hardware identifier that helps protect the key never leaves the Secure Enclave of that machine.
It makes wiping fast and final. Apple describes it as a swift and secure method for wiping content through deletion of the necessary cryptographic material: destroy the keys and the volume is unreadable, with no overwrite pass needed.
It lets a password change without re-encrypting. Changing the password rewraps the key rather than rewriting the disk, which is why a password change is instant.
On one MacTurning FileVault on, on one Mac
Apple's own user guide gives the steps, and two details in it are worth reading before anyone clicks.
The steps. Choose the Apple menu, then System Settings, click Privacy and Security in the sidebar, then click FileVault, then turn it on. You may be asked for your password. You must be an administrator of that Mac to set it up.
The unlock choice. macOS asks how you want to unlock the startup disk if the login password is ever forgotten: through an iCloud account, or with a recovery key it generates for you.
Apple's guidance on the key is blunt: keep a copy somewhere other than the encrypted disk, and not in the same physical location as the Mac. Its warning is blunter still, that if the login password and the recovery key are both lost, the files and settings are lost forever.
Other users on the machine. Their data is encrypted too, and each user unlocks the disk with their own login password. If an Enable Users button appears, each user's password has to be entered before that person can unlock the encrypted disk.
For a company, the iCloud option is the one to think about: it moves the unlock path to a personal Apple account rather than to something the business controls, which is why managed deployments escrow a recovery key instead.
Recovery keyThe recovery key, which is the part that bites
If the password is lost and there is no other unlock path, the data is gone. That is the point of the design, and it makes the recovery key the most consequential decision in a FileVault rollout.
A personal recovery key is generated when a user turns FileVault on themselves. Written on a sticky note it defeats the purpose, and lost with the password it ends the conversation.
An escrowed key is the managed answer. A device management service can specify which certificate is used to asymmetrically encrypt the recovery key for escrow, so the key reaches the MDM encrypted rather than in the clear.
Who can even unlock the volume. Apple's requirement is specific: a user enabled to unlock storage on APFS volumes needs a secure token, and on a Mac with Apple silicon they must be a volume owner. This is the rule behind the classic support case where an administrator account exists on the Mac but cannot unlock it after a restart.
Test the recovery before trusting it. A key in an MDM nobody has ever used to unlock a Mac is an assumption. Unlock one machine with it, in the same week the rollout happens, and write down which users on that Mac could unlock the drive and which could not.
Across a fleetTurning FileVault on across a fleet
Two managed paths exist, and they suit different fleets.
Deferred enablement. Managing FileVault through a device management service is what Apple calls deferred enablement: the profile arrives, and the user is prompted at a logout or login event.
The service can set how many times the user may defer, whether to prompt at logout as well as login, and whether the recovery key is shown to the user at all.
Enforcing it at setup. With the ForceEnableInSetupAssistant key, Macs can be required to turn FileVault on during Setup Assistant, which Apple describes as ensuring that internal storage in managed Macs is always encrypted before it is used.
For new machines that arrive enrolled through Automated Device Enrollment, this is the cleanest option, because no machine ever exists in the unenforced state.
What an RMM alone cannot do. Enabling FileVault, escrowing the key and enforcing it are device management functions, not agent functions, and the same split shows up everywhere else in RMM for Mac. An RMM agent can report whether FileVault is on, and that reporting is how most MSPs discover the gap, but the enforcement belongs to the MDM.
Against BitLockerFileVault and BitLocker, briefly
The two are the same category and differ in where the trust sits.
Disk encryption is one security control among several, and both platforms implement it the same way at a distance. Windows uses BitLocker with a recovery key and a TPM; macOS uses FileVault with the Secure Enclave.
Both encrypt the volume, both hold a key in dedicated hardware, and both hand the administrator the same problem: the recovery key has to be escrowed somewhere the company can reach and an attacker cannot. On a Mac the added wrinkle is the secure token and volume owner rule, which has no direct Windows equivalent.
PitfallsWhere people go wrong
Assuming an unencrypted Mac is unencrypted. On Apple silicon and T2 hardware the volume is encrypted either way. The question is whether the key needs a password, and that is what a compliance report should be asking.
Leaving the recovery key with the user. The one person who forgets the password is the one holding the key.
Enabling it without a volume owner. A management account without a secure token cannot unlock the disk, and the discovery usually happens during an incident.
Believing it protects a running Mac. Disk encryption protects information at rest. A machine that is awake and logged in is decrypted for anyone sitting at it, so access control does the rest: screen locks, multi-factor authentication and session timeouts.
Skipping it because the Mac is desktop-bound. A stolen desktop leaves the building as easily as a laptop, and the drive is the part that matters. Every Mac in the fleet should show FileVault enabled, not just the portable devices.
Counting compliance from the MDM alone. The device management service shows the policy. Whether every Mac actually reports FileVault enabled, with a key escrowed, is a separate report worth reading each month, and it is the report an auditor asks for.
ComparisonWhat changes when FileVault is turned on
| Criterion | FileVault off | FileVault on |
|---|---|---|
| Volume encrypted | Yes, on Apple silicon and T2 | Yes |
| What protects the key | Hardware identifier only | Password and hardware identifier |
| Mac stolen with the disk inside | Unlocks itself | Needs the password |
| Storage chip removed | Unreadable | Unreadable |
| Password required at boot | No | Yes |
| Recovery key exists | No | Yes, escrow it |
| Time to switch on | Immediate, data already encrypted | |
| Wipe is instant | Yes | Yes |
The third row is the whole argument. Everything else follows from it.
FAQFrequently asked questions
What is FileVault disk encryption?
The full-volume encryption built into macOS. It uses the AES-XTS algorithm and, on Apple silicon and T2 Macs, keeps all key handling inside the Secure Enclave, where the keys are never exposed to the CPU.
Is my Mac encrypted without FileVault?
On Apple silicon and T2 Macs, yes, the volume is encrypted, but the key is protected only by the hardware identifier, so the Mac can unlock itself. FileVault adds the user's password to that protection.
Does turning on FileVault take hours?
Not on Apple silicon or T2 Macs. Apple says the process is immediate because the data has already been encrypted. Older Intel Macs without a T2 chip did have to convert the disk.
Does FileVault slow down a Mac?
The encryption runs in dedicated hardware, the AES engine connected to the Secure Enclave, on Apple silicon and T2 Macs. It is also why changing the password does not re-encrypt the volume: Apple lists that as one of the goals of the key hierarchy.
What happens if I lose the password and the recovery key?
The data is unrecoverable. That is the design, not a bug, which is why the recovery key belongs in an escrow the company controls.
How does an MDM escrow the FileVault key?
The device management service specifies a certificate, and the recovery key is asymmetrically encrypted to that certificate before it is escrowed, so it does not travel in the clear.
What is deferred enablement?
Apple's term for managing FileVault through a device management service: the policy is delivered, and FileVault is turned on at a user logout or login. The service can control how many deferrals a user gets and whether the key is shown to them.
Can I require FileVault on a new Mac before anyone uses it?
Yes. The ForceEnableInSetupAssistant key requires FileVault to be turned on during Setup Assistant, so managed Macs are always encrypted with a password before the storage is used.
Why can my admin account not unlock the Mac?
Unlocking an APFS volume requires a secure token, and on Apple silicon the account must also be a volume owner. An account created without one can administer the Mac and still not unlock it at boot.
Does FileVault protect a Mac that is switched on?
No. It protects data at rest. Once the Mac is unlocked, the data is available to whoever is at the keyboard, which is a job for screen locks and session timeouts.
Is FileVault enough for compliance?
It satisfies the encryption-at-rest control that most security frameworks ask for, when it is enabled and the key is escrowed, and it says nothing about the access controls or the rest of the system. What auditors ask for next is evidence: a report showing every Mac with FileVault on, and a key the company can retrieve.
Does FileVault encrypt external drives?
It can encrypt removable storage devices, and Apple notes that they do not use the Secure Enclave for it; the encryption is performed the way an Intel Mac without a T2 chip does it, in software.
Is FileVault the only option for Mac full disk encryption?
For the startup disk, FileVault is the built in and supported way to do Mac full disk encryption, and there is little reason to use anything else. On Macs with Apple silicon or a T2 chip the data is always encrypted in hardware, and turning on FileVault ties the key to your password.
Keep readingRelated concepts
Read next · Cryptography The BitLocker Recovery Key, and Why the Screen Appeared The same problem on Windows: where the recovery key lives and who can reach it. Open this next10 min- Cryptography · 11 min Encryption Algorithms, and the Two Families They Fall Into What AES-XTS is, and where each mode belongs.
- Managed IT · 11 min RMM for Mac, and Why the Agent Only Works as Well as the MDM Behind It Why the enforcement of FileVault belongs to the MDM rather than the RMM agent.
- Cryptography · 10 min Full Disk Encryption, and What It Does Not Protect How full disk encryption works on every platform, and the threats it leaves completely uncovered.