Enabling FileVault disk encryption on macOS devices

FileVault is a native full-disk encryption tool that is available on macOS 15 and later. You can use a FileVault profile in BlackBerry UEM to enable FileVault on macOS devices that are activated with UEM. After an assigned FileVault profile is delivered to a device, the user is prompted for their password on their next login. After they enter their password, FileVault is enabled on the device.

For more information about FileVault, see Apple Platform Deployment: Intro to FileVault.

When you create a FileVault profile, you can configure how each user's personal recovery key is displayed and stored. Options include displaying the key to the user when FileVault is enabled, storing the key in a local file path, and storing the key in the UEM database so that you can view it in the UEM management console. Users require a recovery key to decrypt the disk drive and regain access to their data if they forget their macOS login password. If you do not want to display the recovery key to users or use the key storage options available in the profile, consult Apple's FileVault documentation for the recommended method to obtain a recovery key.

If you use a FileVault profile to turn on FileVault on macOS devices, you cannot turn off FileVault by clearing the "Enable FileVault" setting in the assigned profile. You must follow Apple's documented guidance for turning off FileVault on devices.