Create a FileVault profile

  1. In the management console, on the menu bar, click Policies and profiles > Protection > FileVault.
  2. Click Add icon..
  3. Type a name and description for the profile.
  4. Select the Enable FileVault check box.
  5. If you want to display a personal recovery key to the user after FileVault is enabled on their device, select the Show recovery key to the user after FileVault is enabled check box.
  6. In the Recovery key location field, specify the local file path where macOS will write the user's personal recovery key (for example, /var/db/fv2.plist). It must be an absolute POSIX path to a file in a root-writable directory, and the directories and target file must already exist.

    If you don't specify a recovery key location, macOS does not write the user's personal recovery key anywhere on the device.

  7. If you want to store each user's personal recovery key in the UEM database so you can view it in the UEM management console, select the Store recovery key in BlackBerry UEM check box.
    1. In the Encryption certificate type drop-down list, select the certificate type UEM will use to encrypt the recovery key when it is stored in the UEM database (shared certificate or user credential).
    2. In the Associated shared certificate profile or Associated user credential profile drop-down list, click the appropriate profile to use to encrypt the key.
  8. Click Add.
  • If you created multiple FileVault profiles, rank the profiles.
  • Assign the profile to users and groups. After the profile is applied and FileVault is enabled on devices, the devices display in the management console in Users > Apple Disk Encryption.
  • If you chose to store each user's personal recovery key in the UEM database, you can view the keys in the management console in Users > Apple Disk Encryption (click Show in the Recovery key column), or in a user's device details under Managed device > Disk Encryption.